CVE-2014-6449Juniper Junos vulnerability

CWE-3994 documents4 sources
Severity
5.0MEDIUMNVD
EPSS
0.5%
top 35.23%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 16
Latest updateMay 17

Description

Juniper Junos OS before 12.1X44-D50, 12.1X46 before 12.1X46-D35, 12.1X47 before 12.1X47-D25, 12.3 before 12.3R10, 12.3X48 before 12.3X48-D15, 13.2 before 13.2R8, 13.3 before 13.3R7, 14.1 before 14.1R5, and 14.2 before 14.2R1 do not properly handle TCP packet reassembly, which allows remote attackers to cause a denial of service (buffer consumption) via a crafted sequence of packets "destined to the device."

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages2 packages

NVDjuniper/junos9 versions+8

🔴Vulnerability Details

1
GHSA
GHSA-89gg-wwg4-3jch: Juniper Junos OS before 122022-05-17

📋Vendor Advisories

2
Juniper
CVE-2014-6449: Juniper Junos OS before 12.1X44-D50, 12.1X46 before 12.1X46-D35, 12.1X47 before 12.1X47-D25, 12.3 before 12.3R10, 12.3X48 before 12.3X48-D15, 13.2 bef2015-10-16
BSD
FreeBSD-SA-14:03.openssl: OpenSSL multiple vulnerabilities2014-01-14