7.8

CVE-2014-3817

Juniper Junos 11.4 before 11.4R12, 12.1X44 before 12.1X44-D32, 12.1X45 before 12.1X45-D25, 12.1X46 before 12.1X46-D20, and 12.1X47 before 12.1X47-D10 on SRX Series devices, when NAT protocol translation from IPv4 to IPv6 is enabled, allows remote attackers to cause a denial of service (flowd hang or crash) via a crafted packet.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Juniper ≫ Junos Version 11.4
Juniper ≫ Junos Version 12.1x44
Juniper ≫ Junos Version 12.1x45
Juniper ≫ Junos Version 12.1x46
Juniper ≫ Junos Version 12.1x47
Juniper ≫ Srx100 Version -
Juniper ≫ Srx110 Version -
Juniper ≫ Srx1400 Version -
Juniper ≫ Srx210 Version -
Juniper ≫ Srx220 Version -
Juniper ≫ Srx240 Version -
Juniper ≫ Srx3400 Version -
Juniper ≫ Srx3600 Version -
Juniper ≫ Srx550 Version -
Juniper ≫ Srx5600 Version -
Juniper ≫ Srx5800 Version -
Juniper ≫ Srx650 Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.37% 0.872
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 10 6.9
AV:N/AC:L/Au:N/C:N/I:N/A:C
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://secunia.com/advisories/59136
http://www.securityfocus.com/bid/68545
http://www.securitytracker.com/id/1030558
https://kb.juniper.net/InfoCenter/index?page=content&id=JSA10635
Vendor Advisory