CVE-2014-0612: Medium severity Juniper Junos vulnerability

Published Apr 14, 2014
·
Updated

Unspecified vulnerability in Juniper Junos before 11.4R10-S1, before 11.4R11, 12.1X44 before 12.1X44-D26, 12.1X44 before 12.1X44-D30, 12.1X45 before 12.1X45-D20, and 12.1X46 before 12.1X46-D10, when Dynamic IPsec VPN is configured, allows remote attackers to cause a denial of service (new Dynamic VPN connection failures and CPU and disk consumption) via unknown vectors.

Affected Software

24 affected components
Juniper Junos=11.4
Juniper Junos=12.1
Juniper Junos=12.1x44
Juniper Junos=12.1x45
Juniper Junos=12.1x46
Juniper SRX100
Juniper SRX110
Juniper SRX210
Juniper SRX220
Juniper SRX240
Juniper SRX550
Juniper SRX650
All of the following
Any of the following
Juniper Junos=11.4
Juniper Junos=12.1
Juniper Junos=12.1x44
Juniper Junos=12.1x45
Juniper Junos=12.1x46
Any of the following
Juniper SRX100
Juniper SRX110
Juniper SRX210
Juniper SRX220
Juniper SRX240
Juniper SRX550
Juniper SRX650

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Juniper Junos to a version that resolves this vulnerability.

    Fixed in 11.4R10-S1
  2. Upgrade

    Upgrade Juniper Junos to a version that resolves this vulnerability.

    Fixed in 11.4R11
  3. Upgrade

    Upgrade Juniper Junos to a version that resolves this vulnerability.

    Fixed in 12.1X44
  4. Upgrade

    Upgrade Juniper Junos to a version that resolves this vulnerability.

    Fixed in 12.1X44-D26
  5. Upgrade

    Upgrade Juniper Junos to a version that resolves this vulnerability.

    Fixed in 12.1X44-D30
  6. Upgrade

    Upgrade Juniper Junos to a version that resolves this vulnerability.

    Fixed in 12.1X45
  7. Upgrade

    Upgrade Juniper Junos to a version that resolves this vulnerability.

    Fixed in 12.1X45-D20
  8. Upgrade

    Upgrade Juniper Junos to a version that resolves this vulnerability.

    Fixed in 12.1X46
  9. Upgrade

    Upgrade Juniper Junos to a version that resolves this vulnerability.

    Fixed in 12.1X46-D10

Event History

Apr 14, 2014
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Data Sourced
via NVD·03:09 PM
DescriptionSeverityAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2014-0612?

CVE-2014-0612 is considered to have a moderate severity level due to its potential to cause denial of service.

2

How do I fix CVE-2014-0612?

To remediate CVE-2014-0612, you should upgrade to Junos versions 11.4R10-S1, 12.1X44-D26, or later versions.

3

What systems are affected by CVE-2014-0612?

CVE-2014-0612 affects Juniper Junos software versions prior to 11.4R10-S1 and specific 12.1X series versions.

4

Can CVE-2014-0612 be exploited remotely?

Yes, CVE-2014-0612 can be exploited remotely by attackers to induce a denial of service condition.

5

What configurations expose systems to CVE-2014-0612?

Systems configured with Dynamic IPsec VPN are particularly vulnerable to CVE-2014-0612.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203