PT-2013-5136 · Juniper Networks · Junos

Published

2013-07-11

·

Updated

2013-08-22

·

CVE-2013-4686

CVSS v2.0

7.1

High

VectorAV:N/AC:M/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Junos versions 10.4 through 10.4R13 Junos versions 11.4 through 11.4R7 Junos versions 11.4X27 through 11.4X27.42 Junos versions 12.1 through 12.1R5 Junos versions 12.1X44 through 12.1X44-D19 Junos versions 12.2 through 12.2R3 Junos versions 12.3 through 12.3R1
Description The issue allows remote attackers to cause a denial of service, resulting in a device crash, via a crafted ARP request in certain VLAN configurations where arp-resp and proxy-arp settings are unrestricted.
Recommendations For Junos versions 10.4 through 10.4R13, update to 10.4R14 or later. For Junos versions 11.4 through 11.4R7, update to 11.4R8 or later. For Junos versions 11.4X27 through 11.4X27.42, update to 11.4X27.43 or later. For Junos versions 12.1 through 12.1R5, update to 12.1R6 or later. For Junos versions 12.1X44 through 12.1X44-D19, update to 12.1X44-D20 or later. For Junos versions 12.2 through 12.2R3, update to 12.2R4 or later. For Junos versions 12.3 through 12.3R1, update to 12.3R2 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2013-4686

Affected Products

Junos