VulnerabilityModified
CVE-2014-0617
Juniper Junos 10.4S before 10.4S15, 10.4R before 10.4R16, 11.4 before 11.4R9, and 12.1R before 12.1R7 on SRX Series service gateways allows remote attackers to cause a denial of service (flowd crash) via a crafted IP packet.
HIGH 7.1EPSS 2.34%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.34%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Juniper Junos 10.4S before 10.4S15, 10.4R before 10.4R16, 11.4 before 11.4R9, and 12.1R before 12.1R7 on SRX Series service gateways allows remote attackers to cause a denial of service (flowd crash) via a crafted IP packet.
- CVSS 2.0
- 7.1 HIGHAV:N/AC:M/Au:N/C:N/I:N/A:C
- EPSS
- 2.34% probability · 83th percentile
- CISA KEV
- Not listed
- Affected
- juniper/junos · juniper/srx100 · juniper/srx110 · juniper/srx1400 · juniper/srx210 · juniper/srx220 · juniper/srx240 · juniper/srx3400 · juniper/srx3600 · juniper/srx550 · juniper/srx5600 · juniper/srx5800 · juniper/srx650
- Source
- cve@mitre.org
References
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10610Vendor Advisory
- http://osvdb.org/101863
- http://www.securityfocus.com/bid/64764
- http://www.securitytracker.com/id/1029583
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10610Vendor Advisory
- http://osvdb.org/101863
- http://www.securityfocus.com/bid/64764
- http://www.securitytracker.com/id/1029583
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.