CVE-2014-0618: High severity Juniper Junos vulnerability
Juniper Junos before 10.4 before 10.4R16, 11.4 before 11.4R8, 12.1R before 12.1R7, 12.1X44 before 12.1X44-D20, and 12.1X45 before 12.1X45-D10 on SRX Series service gateways, when used as a UAC enforcer and captive portal is enabled, allows remote attackers to cause a denial of service (flowd crash) via a crafted HTTP message.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Juniper Junos on SRX Series service gatewaysto a version that resolves this vulnerability.Fixed in 10.4R16 - Upgrade
Upgrade
Juniper Junos on SRX Series service gatewaysto a version that resolves this vulnerability.Fixed in 11.4R8 - Upgrade
Upgrade
Juniper Junos on SRX Series service gatewaysto a version that resolves this vulnerability.Fixed in 12.1R7 - Upgrade
Upgrade
Juniper Junos on SRX Series service gatewaysto a version that resolves this vulnerability.Fixed in 12.1X44-D20 - Upgrade
Upgrade
Juniper Junos on SRX Series service gatewaysto a version that resolves this vulnerability.Fixed in 12.1X45-D10
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0618?
CVE-2014-0618 is classified as a high severity vulnerability due to its potential to cause denial of service.
How do I fix CVE-2014-0618?
To fix CVE-2014-0618, upgrade your Junos OS to a version that is not vulnerable, specifically versions 10.4R16, 11.4R8, 12.1R7, 12.1X44-D20, or 12.1X45-D10 and later.
Which devices are affected by CVE-2014-0618?
The affected devices include Juniper SRX Series service gateways running specific versions of Junos OS.
Can CVE-2014-0618 be exploited remotely?
Yes, CVE-2014-0618 can be exploited remotely by attackers, leading to a crash of the flowd process.
What is the impact of CVE-2014-0618 on network operations?
CVE-2014-0618 can lead to a denial of service, impacting network availability and performance.