CVE-2013-4685: Buffer Overflow
Buffer overflow in flowd in Juniper Junos 10.4 before 10.4S14, 11.4 before 11.4R7, 12.1 before 12.1R6, and 12.1X44 before 12.1X44-D15 on SRX devices, when Captive Portal is enabled with the UAC enforcer role, allows remote attackers to execute arbitrary code via crafted HTTP requests, aka PR 849100.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-4685?
CVE-2013-4685 is considered high severity due to its potential to allow remote execution of arbitrary code.
How do I fix CVE-2013-4685?
To fix CVE-2013-4685, you should upgrade your Junos software to versions 10.4S14, 11.4R7, 12.1R6, or 12.1X44-D15 or later.
Which devices are affected by CVE-2013-4685?
CVE-2013-4685 affects Juniper SRX devices running vulnerable versions of Junos with Captive Portal enabled.
What types of attacks can exploit CVE-2013-4685?
CVE-2013-4685 can be exploited by attackers sending crafted HTTP requests that may lead to a buffer overflow.
Is there a workaround for CVE-2013-4685 if I can't immediately upgrade?
A possible workaround for CVE-2013-4685 is to disable the Captive Portal feature until the software can be upgraded.