ID

VAR-201410-0930


CVE

CVE-2014-6379


TITLE

Juniper Junos Vulnerabilities that bypass authentication

Trust: 0.8

sources: JVNDB: JVNDB-2014-004859

DESCRIPTION

Juniper Junos 11.4 before R12, 12.1 before R10, 12.1X44 before D35, 12.1X45 before D25, 12.1X46 before D20, 12.1X47 before D10, 12.2 before R8, 12.2X50 before D70, 12.3 before R6, 13.1 before R4-S3, 13.1X49 before D55, 13.1X50 before D30, 13.2 before R4, 13.2X50 before D20, 13.2X51 before D26 and D30, 13.2X52 before D15, 13.3 before R2, and 14.1 before R1, when a RADIUS accounting server is configured as [system accounting destination radius], creates an entry in /var/etc/pam_radius.conf, which might allow remote attackers to bypass authentication via unspecified vectors. Juniper Junos is prone to a security-bypass vulnerability. An attacker can exploit this issue to bypass certain security restrictions and perform unauthorized actions, like making configuration changes. This may aid in further attacks. Juniper Junos is a set of network operating system of Juniper Networks (Juniper Networks) dedicated to the company's hardware system. The operating system provides a secure programming interface and Junos SDK

Trust: 1.98

sources: NVD: CVE-2014-6379 // JVNDB: JVNDB-2014-004859 // BID: 70365 // VULHUB: VHN-74323

AFFECTED PRODUCTS

vendor:junipermodel:junosscope:eqversion:12.3

Trust: 1.6

vendor:junipermodel:junosscope:eqversion:12.2x50

Trust: 1.6

vendor:junipermodel:junosscope:eqversion:12.1x47

Trust: 1.6

vendor:junipermodel:junosscope:eqversion:12.1

Trust: 1.6

vendor:junipermodel:junosscope:eqversion:11.4

Trust: 1.6

vendor:junipermodel:junosscope:eqversion:12.1x44

Trust: 1.6

vendor:junipermodel:junosscope:eqversion:12.1x46

Trust: 1.6

vendor:junipermodel:junosscope:eqversion:12.1x45

Trust: 1.6

vendor:junipermodel:junosscope:eqversion:12.2

Trust: 1.6

vendor:junipermodel:junosscope:eqversion:12.1r

Trust: 1.6

vendor:junipermodel:junosscope:eqversion:13.1x49

Trust: 1.0

vendor:junipermodel:junosscope:eqversion:13.2x50

Trust: 1.0

vendor:junipermodel:junosscope:eqversion:13.2x52

Trust: 1.0

vendor:junipermodel:junosscope:eqversion:13.1

Trust: 1.0

vendor:junipermodel:junosscope:eqversion:14.1

Trust: 1.0

vendor:junipermodel:junosscope:eqversion:13.1x50

Trust: 1.0

vendor:junipermodel:junosscope:eqversion:13.3

Trust: 1.0

vendor:junipermodel:junosscope:eqversion:13.2

Trust: 1.0

vendor:junipermodel:junosscope:eqversion:13.2x51

Trust: 1.0

vendor:junipermodel:junos osscope:eqversion:13.2x52-d15

Trust: 0.8

vendor:junipermodel:junos osscope:eqversion:12.2r8

Trust: 0.8

vendor:junipermodel:junos osscope:eqversion:12.2x50-d70

Trust: 0.8

vendor:junipermodel:junos osscope:ltversion:12.1x44

Trust: 0.8

vendor:junipermodel:junos osscope:ltversion:13.1x49

Trust: 0.8

vendor:junipermodel:junos osscope:eqversion:13.1x50-d30

Trust: 0.8

vendor:junipermodel:junos osscope:ltversion:11.4

Trust: 0.8

vendor:junipermodel:junos osscope:eqversion:13.1r4-s3

Trust: 0.8

vendor:junipermodel:junos osscope:eqversion:14.1r1

Trust: 0.8

vendor:junipermodel:junos osscope:eqversion:11.4r12

Trust: 0.8

vendor:junipermodel:junos osscope:ltversion:12.3

Trust: 0.8

vendor:junipermodel:junos osscope:eqversion:12.1r10

Trust: 0.8

vendor:junipermodel:junos osscope:eqversion:13.2x51-d26

Trust: 0.8

vendor:junipermodel:junos osscope:ltversion:13.3

Trust: 0.8

vendor:junipermodel:junos osscope:eqversion:12.1x45-d25

Trust: 0.8

vendor:junipermodel:junos osscope:eqversion:12.1x44-d35

Trust: 0.8

vendor:junipermodel:junos osscope:ltversion:13.2

Trust: 0.8

vendor:junipermodel:junos osscope:ltversion:14.1

Trust: 0.8

vendor:junipermodel:junos osscope:eqversion:13.2x51-d30

Trust: 0.8

vendor:junipermodel:junos osscope:ltversion:13.1

Trust: 0.8

vendor:junipermodel:junos osscope:ltversion:13.2x50

Trust: 0.8

vendor:junipermodel:junos osscope:ltversion:12.1x45

Trust: 0.8

vendor:junipermodel:junos osscope:eqversion:13.3r2

Trust: 0.8

vendor:junipermodel:junos osscope:eqversion:13.1x49-d55

Trust: 0.8

vendor:junipermodel:junos osscope:eqversion:12.1x46-d20

Trust: 0.8

vendor:junipermodel:junos osscope:ltversion:13.1x50

Trust: 0.8

vendor:junipermodel:junos osscope:ltversion:12.1x46

Trust: 0.8

vendor:junipermodel:junos osscope:ltversion:12.2

Trust: 0.8

vendor:junipermodel:junos osscope:ltversion:13.2x52

Trust: 0.8

vendor:junipermodel:junos osscope:ltversion:12.1x47

Trust: 0.8

vendor:junipermodel:junos osscope:eqversion:12.1x47-d10

Trust: 0.8

vendor:junipermodel:junos osscope:ltversion:12.2x50

Trust: 0.8

vendor:junipermodel:junos osscope:eqversion:12.3r6

Trust: 0.8

vendor:junipermodel:junos osscope:ltversion:13.2x51

Trust: 0.8

vendor:junipermodel:junos osscope:ltversion:12.1

Trust: 0.8

vendor:junipermodel:junos osscope:eqversion:13.2r4

Trust: 0.8

vendor:junipermodel:junos osscope:eqversion:13.2x50-d20

Trust: 0.8

vendor:junipermodel:junosscope:eqversion: -

Trust: 0.3

vendor:junipermodel:junos 14.1r1scope:neversion: -

Trust: 0.3

vendor:junipermodel:junos 13.3r2scope:neversion: -

Trust: 0.3

vendor:junipermodel:junos 13.2x52-d15scope:neversion: -

Trust: 0.3

vendor:junipermodel:junos 13.2x51-d30scope:neversion: -

Trust: 0.3

vendor:junipermodel:junos 13.2x51-d26scope:neversion: -

Trust: 0.3

vendor:junipermodel:junos 13.2x50-d20scope:neversion: -

Trust: 0.3

vendor:junipermodel:junos 13.2r4scope:neversion: -

Trust: 0.3

vendor:junipermodel:junos 13.1x50-d30scope:neversion: -

Trust: 0.3

vendor:junipermodel:junos 13.1x49-d55scope:neversion: -

Trust: 0.3

vendor:junipermodel:junos 13.1r4-s3scope:neversion: -

Trust: 0.3

vendor:junipermodel:junos 12.3r6scope:neversion: -

Trust: 0.3

vendor:junipermodel:junos 12.2x50-d70scope:neversion: -

Trust: 0.3

vendor:junipermodel:junos 12.2r8scope:neversion: -

Trust: 0.3

vendor:junipermodel:junos 12.1x47-d10scope:neversion: -

Trust: 0.3

vendor:junipermodel:junos 12.1x46-d20scope:neversion: -

Trust: 0.3

vendor:junipermodel:junos 12.1x45-d25scope:neversion: -

Trust: 0.3

vendor:junipermodel:junos 12.1x44-d35scope:neversion: -

Trust: 0.3

vendor:junipermodel:junos 12.1r10scope:neversion: -

Trust: 0.3

vendor:junipermodel:junos 11.4r12scope:neversion: -

Trust: 0.3

sources: BID: 70365 // JVNDB: JVNDB-2014-004859 // CNNVD: CNNVD-201410-262 // NVD: CVE-2014-6379

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2014-6379
value: HIGH

Trust: 1.0

NVD: CVE-2014-6379
value: HIGH

Trust: 0.8

CNNVD: CNNVD-201410-262
value: HIGH

Trust: 0.6

VULHUB: VHN-74323
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2014-6379
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-74323
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-74323 // JVNDB: JVNDB-2014-004859 // CNNVD: CNNVD-201410-262 // NVD: CVE-2014-6379

PROBLEMTYPE DATA

problemtype:CWE-287

Trust: 1.9

sources: VULHUB: VHN-74323 // JVNDB: JVNDB-2014-004859 // NVD: CVE-2014-6379

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201410-262

TYPE

authorization issue

Trust: 0.6

sources: CNNVD: CNNVD-201410-262

CONFIGURATIONS

sources: JVNDB: JVNDB-2014-004859

PATCH

title:JSA10654url:https://kb.juniper.net/InfoCenter/index?page=content&id=JSA10654

Trust: 0.8

sources: JVNDB: JVNDB-2014-004859

EXTERNAL IDS

db:NVDid:CVE-2014-6379

Trust: 2.8

db:JUNIPERid:JSA10654

Trust: 2.0

db:BIDid:70365

Trust: 1.4

db:SECTRACKid:1031010

Trust: 1.1

db:JVNDBid:JVNDB-2014-004859

Trust: 0.8

db:CNNVDid:CNNVD-201410-262

Trust: 0.6

db:VULHUBid:VHN-74323

Trust: 0.1

sources: VULHUB: VHN-74323 // BID: 70365 // JVNDB: JVNDB-2014-004859 // CNNVD: CNNVD-201410-262 // NVD: CVE-2014-6379

REFERENCES

url:https://kb.juniper.net/infocenter/index?page=content&id=jsa10654

Trust: 1.6

url:http://www.securityfocus.com/bid/70365

Trust: 1.1

url:http://www.securitytracker.com/id/1031010

Trust: 1.1

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/96905

Trust: 1.1

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2014-6379

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2014-6379

Trust: 0.8

url:http://www.juniper.net/us/en/products-services/nos/junos/

Trust: 0.3

url:http://kb.juniper.net/infocenter/index?page=content&id=jsa10654&cat=sirt_1&actp=list

Trust: 0.3

url:https://kb.juniper.net/infocenter/index?page=content&id=jsa10654

Trust: 0.1

sources: VULHUB: VHN-74323 // BID: 70365 // JVNDB: JVNDB-2014-004859 // CNNVD: CNNVD-201410-262 // NVD: CVE-2014-6379

CREDITS

Reported by the vendor.

Trust: 0.3

sources: BID: 70365

SOURCES

db:VULHUBid:VHN-74323
db:BIDid:70365
db:JVNDBid:JVNDB-2014-004859
db:CNNVDid:CNNVD-201410-262
db:NVDid:CVE-2014-6379

LAST UPDATE DATE

2025-04-13T23:22:31.964000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-74323date:2017-09-08T00:00:00
db:BIDid:70365date:2014-10-08T00:00:00
db:JVNDBid:JVNDB-2014-004859date:2014-10-21T00:00:00
db:CNNVDid:CNNVD-201410-262date:2014-10-16T00:00:00
db:NVDid:CVE-2014-6379date:2025-04-12T10:46:40.837

SOURCES RELEASE DATE

db:VULHUBid:VHN-74323date:2014-10-14T00:00:00
db:BIDid:70365date:2014-10-08T00:00:00
db:JVNDBid:JVNDB-2014-004859date:2014-10-21T00:00:00
db:CNNVDid:CNNVD-201410-262date:2014-10-15T00:00:00
db:NVDid:CVE-2014-6379date:2014-10-14T14:55:06.413