CVE-2014-3817: Input Validation
Juniper Junos 11.4 before 11.4R12, 12.1X44 before 12.1X44-D32, 12.1X45 before 12.1X45-D25, 12.1X46 before 12.1X46-D20, and 12.1X47 before 12.1X47-D10 on SRX Series devices, when NAT protocol translation from IPv4 to IPv6 is enabled, allows remote attackers to cause a denial of service (flowd hang or crash) via a crafted packet.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-3817?
CVE-2014-3817 is rated as a high severity vulnerability due to its potential to cause a denial of service.
How do I fix CVE-2014-3817?
To mitigate CVE-2014-3817, upgrade to the recommended Junos software versions 11.4R12 or later for 11.4, and 12.1X44-D32 or later for all 12.1X44 versions.
Which devices are affected by CVE-2014-3817?
CVE-2014-3817 affects various SRX Series devices running specific versions of Junos, including SRX100, SRX110, and others listed in the advisory.
What does CVE-2014-3817 exploit?
CVE-2014-3817 exploits a vulnerability in the NAT protocol translation from IPv4 to IPv6, allowing for potential denial of service conditions.
Is there any patch available for CVE-2014-3817?
Yes, patches are available in the recommended software updates that address the vulnerability in CVE-2014-3817.