Vulnerability Name:

CVE-2014-6378 (CCN-96906)

Assigned:2014-10-08
Published:2014-10-08
Updated:2017-09-08
Summary:Juniper Junos 11.4 before R12-S4, 12.1X44 before D35, 12.1X45 before D30, 12.1X46 before D25, 12.1X47 before D10, 12.2 before R9, 12.2X50 before D70, 12.3 before R7, 13.1 before R4 before S3, 13.1X49 before D55, 13.1X50 before D30, 13.2 before R5, 13.2X50 before D20, 13.2X51 before D26 and D30, 13.2X52 before D15, 13.3 before R3, and 14.1 before R1 allows remote attackers to cause a denial of service (router protocol daemon crash) via a crafted RSVP PATH message.
CVSS v3 Severity:7.5 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): High
CVSS v2 Severity:7.8 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C)
5.8 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Complete
7.8 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C)
5.8 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Complete
Vulnerability Type:CWE-399
Vulnerability Consequences:Denial of Service
References:Source: MITRE
Type: CNA
CVE-2014-6378

Source: CCN
Type: Juniper Networks Security Bulletin JSA10652
Junos: Receipt of malformed RSVP packet may lead to denial of service (CVE-2014-6378)

Source: BID
Type: UNKNOWN
70363

Source: CCN
Type: BID-70363
Juniper Junos CVE-2014-6378 Remote Denial of Service Vulnerability

Source: SECTRACK
Type: UNKNOWN
1031008

Source: XF
Type: UNKNOWN
juniper-junos-cve20146378-dos(96906)

Source: XF
Type: UNKNOWN
juniper-junos-cve20146378-dos(96906)

Source: CONFIRM
Type: Vendor Advisory
https://kb.juniper.net/InfoCenter/index?page=content&id=JSA10652

Vulnerable Configuration:Configuration 1:
  • cpe:/o:juniper:junos:11.4:-:*:*:*:*:*:*
  • OR cpe:/o:juniper:junos:11.4:r12:*:*:*:*:*:*
  • OR cpe:/o:juniper:junos:12.1x44:-:*:*:*:*:*:*
  • OR cpe:/o:juniper:junos:12.1x45:-:*:*:*:*:*:*
  • OR cpe:/o:juniper:junos:12.1x46:-:*:*:*:*:*:*
  • OR cpe:/o:juniper:junos:12.1x46:d20:*:*:*:*:*:*
  • OR cpe:/o:juniper:junos:12.1x47:-:*:*:*:*:*:*
  • OR cpe:/o:juniper:junos:12.2:-:*:*:*:*:*:*
  • OR cpe:/o:juniper:junos:12.2:r8-s2:*:*:*:*:*:*
  • OR cpe:/o:juniper:junos:12.2x50:*:*:*:*:*:*:*
  • OR cpe:/o:juniper:junos:12.3:-:*:*:*:*:*:*
  • OR cpe:/o:juniper:junos:13.1:-:*:*:*:*:*:*
  • OR cpe:/o:juniper:junos:13.1:r4-s2:*:*:*:*:*:*
  • OR cpe:/o:juniper:junos:13.1x49:*:*:*:*:*:*:*
  • OR cpe:/o:juniper:junos:13.1x50:*:*:*:*:*:*:*
  • OR cpe:/o:juniper:junos:13.2:-:*:*:*:*:*:*
  • OR cpe:/o:juniper:junos:13.2x50:*:*:*:*:*:*:*
  • OR cpe:/o:juniper:junos:13.2x51:*:*:*:*:*:*:*
  • OR cpe:/o:juniper:junos:13.2x52:*:*:*:*:*:*:*
  • OR cpe:/o:juniper:junos:13.3:-:*:*:*:*:*:*
  • OR cpe:/o:juniper:junos:13.3:r2-s2:*:*:*:*:*:*
  • OR cpe:/o:juniper:junos:14.1:-:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/o:juniper:junos:11.1:*:*:*:*:*:*:*
  • OR cpe:/o:juniper:junos:12.1:-:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    juniper junos 11.4
    juniper junos 11.4 r12
    juniper junos 12.1x44
    juniper junos 12.1x45
    juniper junos 12.1x46
    juniper junos 12.1x46 d20
    juniper junos 12.1x47
    juniper junos 12.2
    juniper junos 12.2 r8-s2
    juniper junos 12.2x50
    juniper junos 12.3
    juniper junos 13.1
    juniper junos 13.1 r4-s2
    juniper junos 13.1x49
    juniper junos 13.1x50
    juniper junos 13.2
    juniper junos 13.2x50
    juniper junos 13.2x51
    juniper junos 13.2x52
    juniper junos 13.3
    juniper junos 13.3 r2-s2
    juniper junos 14.1
    juniper junos 11.1
    juniper junos 12.1