CVE-2014-0612: Medium severity Juniper Junos vulnerability
Unspecified vulnerability in Juniper Junos before 11.4R10-S1, before 11.4R11, 12.1X44 before 12.1X44-D26, 12.1X44 before 12.1X44-D30, 12.1X45 before 12.1X45-D20, and 12.1X46 before 12.1X46-D10, when Dynamic IPsec VPN is configured, allows remote attackers to cause a denial of service (new Dynamic VPN connection failures and CPU and disk consumption) via unknown vectors.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Juniper Junosto a version that resolves this vulnerability.Fixed in 11.4R10-S1 - Upgrade
Upgrade
Juniper Junosto a version that resolves this vulnerability.Fixed in 11.4R11 - Upgrade
Upgrade
Juniper Junosto a version that resolves this vulnerability.Fixed in 12.1X44 - Upgrade
Upgrade
Juniper Junosto a version that resolves this vulnerability.Fixed in 12.1X44-D26 - Upgrade
Upgrade
Juniper Junosto a version that resolves this vulnerability.Fixed in 12.1X44-D30 - Upgrade
Upgrade
Juniper Junosto a version that resolves this vulnerability.Fixed in 12.1X45 - Upgrade
Upgrade
Juniper Junosto a version that resolves this vulnerability.Fixed in 12.1X45-D20 - Upgrade
Upgrade
Juniper Junosto a version that resolves this vulnerability.Fixed in 12.1X46 - Upgrade
Upgrade
Juniper Junosto a version that resolves this vulnerability.Fixed in 12.1X46-D10
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0612?
CVE-2014-0612 is considered to have a moderate severity level due to its potential to cause denial of service.
How do I fix CVE-2014-0612?
To remediate CVE-2014-0612, you should upgrade to Junos versions 11.4R10-S1, 12.1X44-D26, or later versions.
What systems are affected by CVE-2014-0612?
CVE-2014-0612 affects Juniper Junos software versions prior to 11.4R10-S1 and specific 12.1X series versions.
Can CVE-2014-0612 be exploited remotely?
Yes, CVE-2014-0612 can be exploited remotely by attackers to induce a denial of service condition.
What configurations expose systems to CVE-2014-0612?
Systems configured with Dynamic IPsec VPN are particularly vulnerable to CVE-2014-0612.