ID

VAR-201501-0246


CVE

CVE-2014-6384


TITLE

Juniper Junos Vulnerabilities that bypass security policies

Trust: 0.8

sources: JVNDB: JVNDB-2014-007715

DESCRIPTION

Juniper Junos 12.1X44 before 12.1X44-D45, 12.1X46 before 12.1X46-D25, 12.1X47 before 12.1X47-D15, 12.3 before 12.3R9, 13.1 before 13.1R4-S3, 13.2 before 13.2R6, 13.3 before 13.3R5, 14.1 before 14.1R3, and 14.2 before 14.2R1 does not properly handle double quotes in authorization attributes in the TACACS+ configuration, which allows local users to bypass the security policy and execute commands via unspecified vectors. Juniper Junos is prone to local privilege-escalation vulnerability. Local attackers can exploit this issue to gain elevated privileges. Juniper Junos is a set of network operating system of Juniper Networks (Juniper Networks) dedicated to the company's hardware system. The operating system provides a secure programming interface and Junos SDK. The following versions are affected: Juniper Junos 12.1X44 before 12.1X44-D45, 12.1X46 before 12.1X46-D25, 12.1X47 before 12.1X47-D15, 12.3 before 12.3R9, 13.1 before 13.1R4-S3, 13.2R6 Version 13.2 before, version 13.3 before 13.3R5, version 14.1 before 14.1R3, version 14.2 before 14.2R1

Trust: 1.98

sources: NVD: CVE-2014-6384 // JVNDB: JVNDB-2014-007715 // BID: 72077 // VULHUB: VHN-74328

AFFECTED PRODUCTS

vendor:junipermodel:junosscope:eqversion:13.1

Trust: 1.9

vendor:junipermodel:junosscope:eqversion:12.3

Trust: 1.9

vendor:junipermodel:junosscope:eqversion:12.1x44

Trust: 1.9

vendor:junipermodel:junosscope:eqversion:14.1

Trust: 1.3

vendor:junipermodel:junosscope:eqversion:13.3

Trust: 1.3

vendor:junipermodel:junosscope:eqversion:13.2

Trust: 1.3

vendor:junipermodel:junosscope:eqversion:12.1x47

Trust: 1.3

vendor:junipermodel:junosscope:eqversion:12.1x46

Trust: 1.3

vendor:junipermodel:junosscope:eqversion:14.2

Trust: 1.0

vendor:junipermodel:junos osscope:ltversion:13.1

Trust: 0.8

vendor:junipermodel:junos osscope:eqversion:12.1x44-d45

Trust: 0.8

vendor:junipermodel:junos osscope:eqversion:13.1r4-s3

Trust: 0.8

vendor:junipermodel:junos osscope:eqversion:14.2r1

Trust: 0.8

vendor:junipermodel:junos osscope:eqversion:12.1x46-d25

Trust: 0.8

vendor:junipermodel:junos osscope:ltversion:12.3

Trust: 0.8

vendor:junipermodel:junos osscope:eqversion:14.1r3

Trust: 0.8

vendor:junipermodel:junos osscope:eqversion:12.1x47-d15

Trust: 0.8

vendor:junipermodel:junos osscope:ltversion:14.2

Trust: 0.8

vendor:junipermodel:junos osscope:ltversion:12.1x46

Trust: 0.8

vendor:junipermodel:junos osscope:ltversion:12.1x44

Trust: 0.8

vendor:junipermodel:junos osscope:ltversion:13.3

Trust: 0.8

vendor:junipermodel:junos osscope:eqversion:12.3r9

Trust: 0.8

vendor:junipermodel:junos osscope:ltversion:13.2

Trust: 0.8

vendor:junipermodel:junos osscope:ltversion:14.1

Trust: 0.8

vendor:junipermodel:junos osscope:eqversion:13.2r6

Trust: 0.8

vendor:junipermodel:junos osscope:ltversion:12.1x47

Trust: 0.8

vendor:junipermodel:junos osscope:eqversion:13.3r5

Trust: 0.8

vendor:junipermodel:junos 14.2r2scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 14.1x50-d70scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 14.1r4scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 14.1r2scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 14.1r1scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 13.3r6scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 13.3r4scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 13.3r3-s3scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 13.3r3scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 13.3r2-s2scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 13.3r2scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 13.3r1scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 13.2x52-d15scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 13.2x51-d30scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 13.2x51-d26scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 13.2x51-d25scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 13.2x51-d15scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 13.2x50-d20scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 13.2x50-d15.3scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 13.2r5scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 13.2r4scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 13.2r3scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 13.2r2-s2scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 13.2r2scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 13.2r1scope: - version: -

Trust: 0.3

vendor:junipermodel:junos r5scope:eqversion:13.2

Trust: 0.3

vendor:junipermodel:junos 13.1x50-d30scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 13.1x49-d55scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 13.1x49-d49scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 13.1r5scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 13.1r4-s2scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 13.1r4scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 13.1r3-s1scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 13.1r.3-s1scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 12.3r8scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 12.3r7-s1scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 12.3r7scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 12.3r6.6scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 12.3r6scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 12.3r5scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 12.3r4.6scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 12.3r4-s3scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 12.3r4-s2scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 12.3r3scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 12.3r2-s3scope: - version: -

Trust: 0.3

vendor:junipermodel:junos r7scope:eqversion:12.3

Trust: 0.3

vendor:junipermodel:junos 12.2x50-d70scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 12.2x50-d50.1scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 12.2x50-d40.5scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 12.2r9scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 12.2r8-s2scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 12.2r8scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 12.2r7scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 12.2r1.3scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 12.2r1scope: - version: -

Trust: 0.3

vendor:junipermodel:junosscope:eqversion:12.2

Trust: 0.3

vendor:junipermodel:junos 12.1x48-d62scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 12.1x48-d41scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 12.1x47-d11scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 12.1x47-d10scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 12.1x46-d30scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 12.1x46-d20.5scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 12.1x46-d20scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 12.1x46-d15scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 12.1x46-d10scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 12.1x45-d30scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 12.1x45-d25scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 12.1x45-d20scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 12.1x45-d10scope: - version: -

Trust: 0.3

vendor:junipermodel:junos d15scope:eqversion:12.1x45-

Trust: 0.3

vendor:junipermodel:junos d30scope:eqversion:12.1x45

Trust: 0.3

vendor:junipermodel:junosscope:eqversion:12.1x45

Trust: 0.3

vendor:junipermodel:junos 12.1x44-d40scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 12.1x44-d35scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 12.1x44-d34scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 12.1x44-d32scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 12.1x44-d30.4scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 12.1x44-d30scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 12.1x44-d26scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 12.1x44-d20.3scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 12.1x44-d20scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 12.1r9scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 12.1r8-s3scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 12.1r8-s2scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 12.1r7scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 12.1r5.5scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 12.1r5scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 12.1r11scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 12.1r10scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 12.1rscope: - version: -

Trust: 0.3

vendor:junipermodel:junos r11scope:eqversion:12.1

Trust: 0.3

vendor:junipermodel:junosscope:eqversion:12.1

Trust: 0.3

vendor:junipermodel:junos 14.2r1scope:neversion: -

Trust: 0.3

vendor:junipermodel:junos 14.1r3scope:neversion: -

Trust: 0.3

vendor:junipermodel:junos 13.3r5scope:neversion: -

Trust: 0.3

vendor:junipermodel:junos 13.2r6scope:neversion: -

Trust: 0.3

vendor:junipermodel:junos 13.1r4-s3scope:neversion: -

Trust: 0.3

vendor:junipermodel:junos 12.3r9scope:neversion: -

Trust: 0.3

vendor:junipermodel:junos 12.1x47-d15scope:neversion: -

Trust: 0.3

vendor:junipermodel:junos 12.1x46-d25scope:neversion: -

Trust: 0.3

vendor:junipermodel:junos 12.1x44-d45scope:neversion: -

Trust: 0.3

sources: BID: 72077 // JVNDB: JVNDB-2014-007715 // CNNVD: CNNVD-201501-347 // NVD: CVE-2014-6384

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2014-6384
value: MEDIUM

Trust: 1.0

NVD: CVE-2014-6384
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-201501-347
value: MEDIUM

Trust: 0.6

VULHUB: VHN-74328
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2014-6384
severity: MEDIUM
baseScore: 6.9
vectorString: AV:L/AC:M/AU:N/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.4
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-74328
severity: MEDIUM
baseScore: 6.9
vectorString: AV:L/AC:M/AU:N/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.4
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-74328 // JVNDB: JVNDB-2014-007715 // CNNVD: CNNVD-201501-347 // NVD: CVE-2014-6384

PROBLEMTYPE DATA

problemtype:CWE-264

Trust: 1.9

sources: VULHUB: VHN-74328 // JVNDB: JVNDB-2014-007715 // NVD: CVE-2014-6384

THREAT TYPE

local

Trust: 0.9

sources: BID: 72077 // CNNVD: CNNVD-201501-347

TYPE

permissions and access control

Trust: 0.6

sources: CNNVD: CNNVD-201501-347

CONFIGURATIONS

sources: JVNDB: JVNDB-2014-007715

PATCH

title:JSA10667url:https://kb.juniper.net/InfoCenter/index?page=content&id=JSA10667

Trust: 0.8

sources: JVNDB: JVNDB-2014-007715

EXTERNAL IDS

db:NVDid:CVE-2014-6384

Trust: 2.8

db:BIDid:72077

Trust: 2.0

db:JUNIPERid:JSA10667

Trust: 2.0

db:SECTRACKid:1031547

Trust: 1.1

db:JVNDBid:JVNDB-2014-007715

Trust: 0.8

db:CNNVDid:CNNVD-201501-347

Trust: 0.7

db:VULHUBid:VHN-74328

Trust: 0.1

sources: VULHUB: VHN-74328 // BID: 72077 // JVNDB: JVNDB-2014-007715 // CNNVD: CNNVD-201501-347 // NVD: CVE-2014-6384

REFERENCES

url:http://www.securityfocus.com/bid/72077

Trust: 1.7

url:https://kb.juniper.net/infocenter/index?page=content&id=jsa10667

Trust: 1.6

url:http://www.securitytracker.com/id/1031547

Trust: 1.1

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2014-6384

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2014-6384

Trust: 0.8

url:http://www.juniper.net

Trust: 0.3

url:http://kb.juniper.net/infocenter/index?page=content&id=jsa10667&cat=sirt_1&actp=list

Trust: 0.3

url:https://kb.juniper.net/infocenter/index?page=content&id=jsa10667

Trust: 0.1

sources: VULHUB: VHN-74328 // BID: 72077 // JVNDB: JVNDB-2014-007715 // CNNVD: CNNVD-201501-347 // NVD: CVE-2014-6384

CREDITS

Juniper

Trust: 0.9

sources: BID: 72077 // CNNVD: CNNVD-201501-347

SOURCES

db:VULHUBid:VHN-74328
db:BIDid:72077
db:JVNDBid:JVNDB-2014-007715
db:CNNVDid:CNNVD-201501-347
db:NVDid:CVE-2014-6384

LAST UPDATE DATE

2025-04-13T23:25:20.154000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-74328date:2015-01-26T00:00:00
db:BIDid:72077date:2015-01-14T00:00:00
db:JVNDBid:JVNDB-2014-007715date:2015-01-23T00:00:00
db:CNNVDid:CNNVD-201501-347date:2015-01-19T00:00:00
db:NVDid:CVE-2014-6384date:2025-04-12T10:46:40.837

SOURCES RELEASE DATE

db:VULHUBid:VHN-74328date:2015-01-16T00:00:00
db:BIDid:72077date:2015-01-14T00:00:00
db:JVNDBid:JVNDB-2014-007715date:2015-01-23T00:00:00
db:CNNVDid:CNNVD-201501-347date:2015-01-16T00:00:00
db:NVDid:CVE-2014-6384date:2015-01-16T16:59:05.343