ID

VAR-201410-0970


CVE

CVE-2014-6378


TITLE

Juniper Junos Service disruption in (DoS) Vulnerabilities

Trust: 0.8

sources: JVNDB: JVNDB-2014-004858

DESCRIPTION

Juniper Junos 11.4 before R12-S4, 12.1X44 before D35, 12.1X45 before D30, 12.1X46 before D25, 12.1X47 before D10, 12.2 before R9, 12.2X50 before D70, 12.3 before R7, 13.1 before R4 before S3, 13.1X49 before D55, 13.1X50 before D30, 13.2 before R5, 13.2X50 before D20, 13.2X51 before D26 and D30, 13.2X52 before D15, 13.3 before R3, and 14.1 before R1 allows remote attackers to cause a denial of service (router protocol daemon crash) via a crafted RSVP PATH message. Juniper Junos is prone to a remote denial-of-service vulnerability. Exploiting this issue may allow remote attackers to hang or crash the RPD (Routing Protocol Daemon), causing denial-of-service conditions. Juniper Junos is a set of network operating system of Juniper Networks (Juniper Networks) dedicated to the company's hardware system. The operating system provides a secure programming interface and Junos SDK. The following versions are affected: 11.4 before Juniper Junos R12-S4, 12.1X44 before D35, 12.1X45 before D30, 12.1X46 before D25, 12.1X47 before D10, 12.2 before R9, 12.2X50 before D70, R7 Version 12.3 before, Version 13.1 before R4-S3, Version 13.1X49 before D55, Version 13.1X50 before D30, Version 13.2 before R5, Version 13.2X50 before D20, Version 13.2X51 before D26, Version D30, Version 13.2X52 before D15, R3 Version 13.3 before R1, version 14.1 before R1

Trust: 1.98

sources: NVD: CVE-2014-6378 // JVNDB: JVNDB-2014-004858 // BID: 70363 // VULHUB: VHN-74322

AFFECTED PRODUCTS

vendor:junipermodel:junosscope:eqversion:12.2x50

Trust: 1.6

vendor:junipermodel:junosscope:eqversion:12.1x47

Trust: 1.6

vendor:junipermodel:junosscope:eqversion:11.4

Trust: 1.6

vendor:junipermodel:junosscope:eqversion:12.1x46

Trust: 1.6

vendor:junipermodel:junosscope:eqversion:12.1x44

Trust: 1.6

vendor:junipermodel:junosscope:eqversion:12.1x45

Trust: 1.6

vendor:junipermodel:junosscope:eqversion:12.2

Trust: 1.6

vendor:junipermodel:junosscope:eqversion:13.1x49

Trust: 1.0

vendor:junipermodel:junosscope:eqversion:13.2x50

Trust: 1.0

vendor:junipermodel:junosscope:eqversion:13.1x50

Trust: 1.0

vendor:junipermodel:junosscope:eqversion:13.2x52

Trust: 1.0

vendor:junipermodel:junosscope:eqversion:12.3

Trust: 1.0

vendor:junipermodel:junosscope:eqversion:13.1

Trust: 1.0

vendor:junipermodel:junosscope:eqversion:13.3

Trust: 1.0

vendor:junipermodel:junosscope:eqversion:13.2

Trust: 1.0

vendor:junipermodel:junosscope:eqversion:13.2x51

Trust: 1.0

vendor:junipermodel:junosscope:eqversion:14.1

Trust: 1.0

vendor:junipermodel:junos osscope:eqversion:13.2x52-d15

Trust: 0.8

vendor:junipermodel:junos osscope:eqversion:13.2r5

Trust: 0.8

vendor:junipermodel:junos osscope:eqversion:12.2x50-d70

Trust: 0.8

vendor:junipermodel:junos osscope:ltversion:12.1x44

Trust: 0.8

vendor:junipermodel:junos osscope:ltversion:13.1x49

Trust: 0.8

vendor:junipermodel:junos osscope:eqversion:13.1x50-d30

Trust: 0.8

vendor:junipermodel:junos osscope:ltversion:11.4

Trust: 0.8

vendor:junipermodel:junos osscope:eqversion:13.1r4-s3

Trust: 0.8

vendor:junipermodel:junos osscope:eqversion:14.1r1

Trust: 0.8

vendor:junipermodel:junos osscope:ltversion:12.3

Trust: 0.8

vendor:junipermodel:junos osscope:eqversion:13.2x51-d26

Trust: 0.8

vendor:junipermodel:junos osscope:ltversion:13.3

Trust: 0.8

vendor:junipermodel:junos osscope:eqversion:12.1x44-d35

Trust: 0.8

vendor:junipermodel:junos osscope:eqversion:11.4r12-s4

Trust: 0.8

vendor:junipermodel:junos osscope:ltversion:13.2

Trust: 0.8

vendor:junipermodel:junos osscope:ltversion:14.1

Trust: 0.8

vendor:junipermodel:junos osscope:eqversion:13.2x51-d30

Trust: 0.8

vendor:junipermodel:junos osscope:ltversion:13.1

Trust: 0.8

vendor:junipermodel:junos osscope:ltversion:13.2x50

Trust: 0.8

vendor:junipermodel:junos osscope:ltversion:12.1x45

Trust: 0.8

vendor:junipermodel:junos osscope:eqversion:13.1x49-d55

Trust: 0.8

vendor:junipermodel:junos osscope:ltversion:13.1x50

Trust: 0.8

vendor:junipermodel:junos osscope:ltversion:12.1x46

Trust: 0.8

vendor:junipermodel:junos osscope:ltversion:12.2

Trust: 0.8

vendor:junipermodel:junos osscope:ltversion:13.2x52

Trust: 0.8

vendor:junipermodel:junos osscope:ltversion:12.1x47

Trust: 0.8

vendor:junipermodel:junos osscope:eqversion:13.3r3

Trust: 0.8

vendor:junipermodel:junos osscope:eqversion:12.1x47-d10

Trust: 0.8

vendor:junipermodel:junos osscope:eqversion:12.1x46-d25

Trust: 0.8

vendor:junipermodel:junos osscope:ltversion:12.2x50

Trust: 0.8

vendor:junipermodel:junos osscope:ltversion:13.2x51

Trust: 0.8

vendor:junipermodel:junos osscope:eqversion:12.1x45-d30

Trust: 0.8

vendor:junipermodel:junos osscope:eqversion:12.3r7

Trust: 0.8

vendor:junipermodel:junos osscope:eqversion:13.2x50-d20

Trust: 0.8

vendor:junipermodel:junos osscope:eqversion:12.2r9

Trust: 0.8

sources: JVNDB: JVNDB-2014-004858 // CNNVD: CNNVD-201410-261 // NVD: CVE-2014-6378

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2014-6378
value: HIGH

Trust: 1.0

NVD: CVE-2014-6378
value: HIGH

Trust: 0.8

CNNVD: CNNVD-201410-261
value: HIGH

Trust: 0.6

VULHUB: VHN-74322
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2014-6378
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-74322
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-74322 // JVNDB: JVNDB-2014-004858 // CNNVD: CNNVD-201410-261 // NVD: CVE-2014-6378

PROBLEMTYPE DATA

problemtype:CWE-399

Trust: 1.9

sources: VULHUB: VHN-74322 // JVNDB: JVNDB-2014-004858 // NVD: CVE-2014-6378

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201410-261

TYPE

resource management error

Trust: 0.6

sources: CNNVD: CNNVD-201410-261

CONFIGURATIONS

sources: JVNDB: JVNDB-2014-004858

PATCH

title:JSA10652url:https://kb.juniper.net/InfoCenter/index?page=content&id=JSA10652

Trust: 0.8

sources: JVNDB: JVNDB-2014-004858

EXTERNAL IDS

db:NVDid:CVE-2014-6378

Trust: 2.8

db:JUNIPERid:JSA10652

Trust: 2.0

db:BIDid:70363

Trust: 1.4

db:SECTRACKid:1031008

Trust: 1.1

db:JVNDBid:JVNDB-2014-004858

Trust: 0.8

db:CNNVDid:CNNVD-201410-261

Trust: 0.7

db:VULHUBid:VHN-74322

Trust: 0.1

sources: VULHUB: VHN-74322 // BID: 70363 // JVNDB: JVNDB-2014-004858 // CNNVD: CNNVD-201410-261 // NVD: CVE-2014-6378

REFERENCES

url:https://kb.juniper.net/infocenter/index?page=content&id=jsa10652

Trust: 1.6

url:http://www.securityfocus.com/bid/70363

Trust: 1.1

url:http://www.securitytracker.com/id/1031008

Trust: 1.1

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/96906

Trust: 1.1

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2014-6378

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2014-6378

Trust: 0.8

url:http://kb.juniper.net/infocenter/index?page=content&id=jsa10652&cat=sirt_1&actp=list

Trust: 0.3

url:http://www.juniper.net/

Trust: 0.3

url:https://kb.juniper.net/infocenter/index?page=content&id=jsa10652

Trust: 0.1

sources: VULHUB: VHN-74322 // BID: 70363 // JVNDB: JVNDB-2014-004858 // CNNVD: CNNVD-201410-261 // NVD: CVE-2014-6378

CREDITS

The vendor reported this issue.

Trust: 0.3

sources: BID: 70363

SOURCES

db:VULHUBid:VHN-74322
db:BIDid:70363
db:JVNDBid:JVNDB-2014-004858
db:CNNVDid:CNNVD-201410-261
db:NVDid:CVE-2014-6378

LAST UPDATE DATE

2025-04-13T23:41:27.535000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-74322date:2017-09-08T00:00:00
db:BIDid:70363date:2014-10-09T00:00:00
db:JVNDBid:JVNDB-2014-004858date:2014-10-21T00:00:00
db:CNNVDid:CNNVD-201410-261date:2014-10-16T00:00:00
db:NVDid:CVE-2014-6378date:2025-04-12T10:46:40.837

SOURCES RELEASE DATE

db:VULHUBid:VHN-74322date:2014-10-14T00:00:00
db:BIDid:70363date:2014-10-09T00:00:00
db:JVNDBid:JVNDB-2014-004858date:2014-10-21T00:00:00
db:CNNVDid:CNNVD-201410-261date:2014-10-15T00:00:00
db:NVDid:CVE-2014-6378date:2014-10-14T14:55:06.383