6.8

CVE-2014-3825

The Juniper SRX Series devices with Junos 11.4 before 11.4R12-S4, 12.1X44 before 12.1X44-D40, 12.1X45 before 12.1X45-D30, 12.1X46 before 12.1X46-D25, and 12.1X47 before 12.1X47-D10, when an Application Layer Gateway (ALG) is enabled, allows remote attackers to cause a denial of service (flowd crash) via a crafted packet.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Juniper ≫ Junos Version 11.4
Juniper ≫ Junos Version 12.1
Juniper ≫ Junos Version 12.1x44
Juniper ≫ Junos Version 12.1x45
Juniper ≫ Junos Version 12.1x46
Juniper ≫ Junos Version 12.1x47
Juniper ≫ Srx100 Version -
Juniper ≫ Srx110 Version -
Juniper ≫ Srx1400 Version -
Juniper ≫ Srx210 Version -
Juniper ≫ Srx220 Version -
Juniper ≫ Srx240 Version -
Juniper ≫ Srx3400 Version -
Juniper ≫ Srx3600 Version -
Juniper ≫ Srx550 Version -
Juniper ≫ Srx5600 Version -
Juniper ≫ Srx5800 Version -
Juniper ≫ Srx650 Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.04% 0.786
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://www.securitytracker.com/id/1031007
https://kb.juniper.net/InfoCenter/index?page=content&id=JSA10650
Vendor Advisory