Vulnerability Name: | CVE-2013-6014 (CCN-88325) | ||||||||||||
Assigned: | 2013-10-04 | ||||||||||||
Published: | 2013-10-04 | ||||||||||||
Updated: | 2019-09-27 | ||||||||||||
Summary: | Juniper Junos 10.4 before 10.4S15, 11.4 before 11.4R9, 11.4X27 before 11.4X27.44, 12.1 before 12.1R7, 12.1X44 before 12.1X44-D20, 12.1X45 before 12.1X45-D15, 12.2 before 12.2R6, 12.3 before 12.3R3, 13.1 before 13.1R3, and 13.2 before 13.2R1, when Proxy ARP is enabled on an unnumbered interface, allows remote attackers to perform ARP poisoning attacks and possibly obtain sensitive information via a crafted ARP message. | ||||||||||||
CVSS v3 Severity: | 9.3 Critical (CVSS v3.1 Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:H)
| ||||||||||||
CVSS v2 Severity: | 6.1 Medium (CVSS v2 Vector: AV:A/AC:L/Au:N/C:N/I:C/A:N) 4.5 Medium (Temporal CVSS v2 Vector: AV:A/AC:L/Au:N/C:N/I:C/A:N/E:U/RL:OF/RC:C)
4.5 Medium (CCN Temporal CVSS v2 Vector: AV:A/AC:L/Au:N/C:N/I:N/A:C/E:U/RL:OF/RC:C)
| ||||||||||||
Vulnerability Type: | CWE-200 | ||||||||||||
Vulnerability Consequences: | Denial of Service | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2013-6014 Source: XF Type: UNKNOWN juniper-junos-cve20136014-dos(88325) Source: CCN Type: JSA10595 Junos: Security issue with Proxy ARP enabled on unnumbered interface (CVE-2013-6014) Source: CONFIRM Type: Vendor Advisory https://kb.juniper.net/InfoCenter/index?page=content&id=JSA10595 | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||
BACK |