CVE-2013-4688: High severity junos os evolved vulnerability
Published Jul 11, 2013
·Updated
flowd in Juniper Junos 10.4 before 10.4R11 on SRX devices, when the MSRPC Application Layer Gateway (ALG) is enabled, allows remote attackers to cause a denial of service (daemon crash) via crafted MSRPC requests, aka PR 772834.
Affected Software
13 affected components
Juniper Junos=10.4
Juniper SRX100
Juniper SRX110
Juniper SRX1400
Juniper SRX210
Juniper SRX220
Juniper SRX240
Juniper SRX3400
Juniper SRX3600
Juniper SRX550
Juniper SRX5600
Juniper SRX5800
Juniper SRX650
Event History
Jul 11, 2013
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-4688?
CVE-2013-4688 has a severity rating that indicates it may lead to a denial of service on affected Juniper devices.
2
How do I fix CVE-2013-4688?
To address CVE-2013-4688, it is recommended to upgrade Juniper Junos to version 10.4R11 or later.
3
Which devices are affected by CVE-2013-4688?
CVE-2013-4688 affects various Juniper SRX devices running Junos 10.4 before 10.4R11.
4
What exploit does CVE-2013-4688 enable?
CVE-2013-4688 enables remote attackers to cause a denial of service via crafted MSRPC requests.
5
What is the specific function affected by CVE-2013-4688?
CVE-2013-4688 affects the MSRPC Application Layer Gateway (ALG) when it is enabled on Juniper devices.