PT-2014-5530 · Juniper Networks · Srx Series+1

Published

2014-10-14

·

Updated

2015-11-05

·

CVE-2014-3825

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Juniper SRX Series devices with Junos versions prior to 11.4R12-S4 Juniper SRX Series devices with Junos versions 12.1X44 before 12.1X44-D40 Juniper SRX Series devices with Junos versions 12.1X45 before 12.1X45-D30 Juniper SRX Series devices with Junos versions 12.1X46 before 12.1X46-D25 Juniper SRX Series devices with Junos versions 12.1X47 before 12.1X47-D10
Description The issue allows remote attackers to cause a denial of service, resulting in a flowd crash, via a crafted packet when an Application Layer Gateway (ALG) is enabled.
Recommendations For Junos versions prior to 11.4R12-S4, update to 11.4R12-S4 or later. For Junos versions 12.1X44 before 12.1X44-D40, update to 12.1X44-D40 or later. For Junos versions 12.1X45 before 12.1X45-D30, update to 12.1X45-D30 or later. For Junos versions 12.1X46 before 12.1X46-D25, update to 12.1X46-D25 or later. For Junos versions 12.1X47 before 12.1X47-D10, update to 12.1X47-D10 or later.

Fix

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-3825

Affected Products

Junos
Srx Series