PT-2014-7198 · Juniper Networks · Junose
Publicado
2014-10-14
·
Atualizado
2017-09-08
·
CVE-2014-6377
CVSS v2.0
7.8
Alta
| Vetor | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Juniper JunosE versions prior to 13.3.3p0-1
Juniper JunosE versions 14.x prior to 14.3.2
Juniper JunosE versions 15.x prior to 15.1.0
Description
The issue allows remote attackers to cause a denial of service via a crafted ICMP packet to the interface or loopback IP address, triggering a processor exception in ip RxData 8. This occurs when DEBUG severity icmpTraffic logging is enabled.
Recommendations
For Juniper JunosE versions prior to 13.3.3p0-1, update to version 13.3.3p0-1 or later.
For Juniper JunosE versions 14.x prior to 14.3.2, update to version 14.3.2 or later.
For Juniper JunosE versions 15.x prior to 15.1.0, update to version 15.1.0 or later.
As a temporary workaround, consider disabling DEBUG severity icmpTraffic logging until a patch is available.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Junose