Vulnerability Name:

CVE-2014-6379 (CCN-96905)

Assigned:2014-10-08
Published:2014-10-08
Updated:2017-09-08
Summary:Juniper Junos 11.4 before R12, 12.1 before R10, 12.1X44 before D35, 12.1X45 before D25, 12.1X46 before D20, 12.1X47 before D10, 12.2 before R8, 12.2X50 before D70, 12.3 before R6, 13.1 before R4-S3, 13.1X49 before D55, 13.1X50 before D30, 13.2 before R4, 13.2X50 before D20, 13.2X51 before D26 and D30, 13.2X52 before D15, 13.3 before R2, and 14.1 before R1, when a RADIUS accounting server is configured as [system accounting destination radius], creates an entry in /var/etc/pam_radius.conf, which might allow remote attackers to bypass authentication via unspecified vectors.
CVSS v3 Severity:4.6 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): Low
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): None
CVSS v2 Severity:7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
5.5 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
5.5 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:P/A:N)
4.0 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:P/A:N/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): None
Vulnerability Type:CWE-287
Vulnerability Consequences:Bypass Security
References:Source: MITRE
Type: CNA
CVE-2014-6379

Source: CCN
Type: Juniper Networks Security Bulletin JSA10654
Junos: RADIUS accounting servers create additional entries in pam_radius.conf (CVE-2014-6379)

Source: BID
Type: UNKNOWN
70365

Source: CCN
Type: BID-70365
Juniper Junos CVE-2014-6379 Security Bypass Vulnerability

Source: SECTRACK
Type: UNKNOWN
1031010

Source: XF
Type: UNKNOWN
juniper-junos-cve20146379-sec-bypass(96905)

Source: XF
Type: UNKNOWN
juniper-junos-cve20146379-sec-bypass(96905)

Source: CONFIRM
Type: Vendor Advisory
https://kb.juniper.net/InfoCenter/index?page=content&id=JSA10654

Vulnerable Configuration:Configuration 1:
  • cpe:/o:juniper:junos:11.4:-:*:*:*:*:*:*
  • OR cpe:/o:juniper:junos:12.1:-:*:*:*:*:*:*
  • OR cpe:/o:juniper:junos:12.1r:*:*:*:*:*:*:*
  • OR cpe:/o:juniper:junos:12.1x44:-:*:*:*:*:*:*
  • OR cpe:/o:juniper:junos:12.1x45:-:*:*:*:*:*:*
  • OR cpe:/o:juniper:junos:12.1x46:-:*:*:*:*:*:*
  • OR cpe:/o:juniper:junos:12.1x47:-:*:*:*:*:*:*
  • OR cpe:/o:juniper:junos:12.2:-:*:*:*:*:*:*
  • OR cpe:/o:juniper:junos:12.2x50:*:*:*:*:*:*:*
  • OR cpe:/o:juniper:junos:12.3:-:*:*:*:*:*:*
  • OR cpe:/o:juniper:junos:12.3:r7:*:*:*:*:*:*
  • OR cpe:/o:juniper:junos:13.1:-:*:*:*:*:*:*
  • OR cpe:/o:juniper:junos:13.1:r4-s2:*:*:*:*:*:*
  • OR cpe:/o:juniper:junos:13.1x49:*:*:*:*:*:*:*
  • OR cpe:/o:juniper:junos:13.1x50:*:*:*:*:*:*:*
  • OR cpe:/o:juniper:junos:13.2:-:*:*:*:*:*:*
  • OR cpe:/o:juniper:junos:13.2x50:*:*:*:*:*:*:*
  • OR cpe:/o:juniper:junos:13.2x51:*:*:*:*:*:*:*
  • OR cpe:/o:juniper:junos:13.2x52:*:*:*:*:*:*:*
  • OR cpe:/o:juniper:junos:13.3:-:*:*:*:*:*:*
  • OR cpe:/o:juniper:junos:14.1:-:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/o:juniper:junos:11.1:*:*:*:*:*:*:*
  • OR cpe:/o:juniper:junos:12.1:-:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    juniper junos 11.4
    juniper junos 12.1
    juniper junos 12.1r
    juniper junos 12.1x44
    juniper junos 12.1x45
    juniper junos 12.1x46
    juniper junos 12.1x47
    juniper junos 12.2
    juniper junos 12.2x50
    juniper junos 12.3
    juniper junos 12.3 r7
    juniper junos 13.1
    juniper junos 13.1 r4-s2
    juniper junos 13.1x49
    juniper junos 13.1x50
    juniper junos 13.2
    juniper junos 13.2x50
    juniper junos 13.2x51
    juniper junos 13.2x52
    juniper junos 13.3
    juniper junos 14.1
    juniper junos 11.1
    juniper junos 12.1