CVE-2014-6382: Input Validation
The Juniper MX Series routers with Junos 13.3R3 through 13.3Rx before 13.3R6, 14.1 before 14.1R4, 14.1X50 before 14.1X50-D70, and 14.2 before 14.2R2, when configured as a broadband edge (BBE) router, allows remote attackers to cause a denial of service (jpppd crash and restart) by sending a crafted PAP Authenticate-Request after the PPPoE Discovery and LCP phase are complete.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-6382?
CVE-2014-6382 is classified as a high severity vulnerability that allows remote attackers to cause a denial of service.
How do I fix CVE-2014-6382?
To fix CVE-2014-6382, upgrade your Junos version to 13.3R6, 14.1R4, 14.1X50-D70 or 14.2R2 or later.
Which devices are affected by CVE-2014-6382?
The affected devices are Juniper MX Series routers running Junos versions 13.3R3 through 14.2R1.
What type of attack does CVE-2014-6382 enable?
CVE-2014-6382 enables remote denial of service attacks that can crash and restart the jpppd service.
Is CVE-2014-6382 related to specific Junos configurations?
Yes, CVE-2014-6382 occurs when Juniper MX Series routers are configured as broadband edge (BBE) routers.