CVE-2014-0618: High severity Juniper Junos vulnerability

Published Jan 11, 2014
·
Updated

Juniper Junos before 10.4 before 10.4R16, 11.4 before 11.4R8, 12.1R before 12.1R7, 12.1X44 before 12.1X44-D20, and 12.1X45 before 12.1X45-D10 on SRX Series service gateways, when used as a UAC enforcer and captive portal is enabled, allows remote attackers to cause a denial of service (flowd crash) via a crafted HTTP message.

Affected Software

34 affected components
Juniper Junos=10.4
Juniper Junos=11.4
Juniper Junos=12.1r
Juniper Junos=12.1x44
Juniper Junos=12.1x45
Juniper SRX100
Juniper SRX110
Juniper SRX1400
Juniper SRX210
Juniper SRX220
Juniper SRX240
Juniper SRX3400
Juniper SRX3600
Juniper SRX550
Juniper SRX5600
Juniper SRX5800
Juniper SRX650
All of the following
Any of the following
Juniper Junos=10.4
Juniper Junos=11.4
Juniper Junos=12.1r
Juniper Junos=12.1x44
Juniper Junos=12.1x45
Any of the following
Juniper SRX100
Juniper SRX110
Juniper SRX1400
Juniper SRX210
Juniper SRX220
Juniper SRX240
Juniper SRX3400
Juniper SRX3600
Juniper SRX550
Juniper SRX5600
Juniper SRX5800
Juniper SRX650

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Juniper Junos on SRX Series service gateways to a version that resolves this vulnerability.

    Fixed in 10.4R16
  2. Upgrade

    Upgrade Juniper Junos on SRX Series service gateways to a version that resolves this vulnerability.

    Fixed in 11.4R8
  3. Upgrade

    Upgrade Juniper Junos on SRX Series service gateways to a version that resolves this vulnerability.

    Fixed in 12.1R7
  4. Upgrade

    Upgrade Juniper Junos on SRX Series service gateways to a version that resolves this vulnerability.

    Fixed in 12.1X44-D20
  5. Upgrade

    Upgrade Juniper Junos on SRX Series service gateways to a version that resolves this vulnerability.

    Fixed in 12.1X45-D10

Event History

Jan 11, 2014
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Data Sourced
via NVD·04:44 AM
DescriptionSeverityAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2014-0618?

CVE-2014-0618 is classified as a high severity vulnerability due to its potential to cause denial of service.

2

How do I fix CVE-2014-0618?

To fix CVE-2014-0618, upgrade your Junos OS to a version that is not vulnerable, specifically versions 10.4R16, 11.4R8, 12.1R7, 12.1X44-D20, or 12.1X45-D10 and later.

3

Which devices are affected by CVE-2014-0618?

The affected devices include Juniper SRX Series service gateways running specific versions of Junos OS.

4

Can CVE-2014-0618 be exploited remotely?

Yes, CVE-2014-0618 can be exploited remotely by attackers, leading to a crash of the flowd process.

5

What is the impact of CVE-2014-0618 on network operations?

CVE-2014-0618 can lead to a denial of service, impacting network availability and performance.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203