CVE Vulnerabilities

CVE-2014-6384

Published: Jan 16, 2015 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.9 MEDIUM
AV:L/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Juniper Junos 12.1X44 before 12.1X44-D45, 12.1X46 before 12.1X46-D25, 12.1X47 before 12.1X47-D15, 12.3 before 12.3R9, 13.1 before 13.1R4-S3, 13.2 before 13.2R6, 13.3 before 13.3R5, 14.1 before 14.1R3, and 14.2 before 14.2R1 does not properly handle double quotes in authorization attributes in the TACACS+ configuration, which allows local users to bypass the security policy and execute commands via unspecified vectors.

Affected Software

NameVendorStart VersionEnd Version
JunosJuniper12.1x44 (including)12.1x44 (including)
JunosJuniper12.1x44-d10 (including)12.1x44-d10 (including)
JunosJuniper12.1x44-d15 (including)12.1x44-d15 (including)
JunosJuniper12.1x44-d20 (including)12.1x44-d20 (including)
JunosJuniper12.1x44-d25 (including)12.1x44-d25 (including)
JunosJuniper12.1x44-d30 (including)12.1x44-d30 (including)
JunosJuniper12.1x44-d35 (including)12.1x44-d35 (including)
JunosJuniper12.1x44-d40 (including)12.1x44-d40 (including)
JunosJuniper12.1x46 (including)12.1x46 (including)
JunosJuniper12.1x46-d10 (including)12.1x46-d10 (including)
JunosJuniper12.1x46-d15 (including)12.1x46-d15 (including)
JunosJuniper12.1x46-d20 (including)12.1x46-d20 (including)
JunosJuniper12.1x47 (including)12.1x47 (including)
JunosJuniper12.1x47-d10 (including)12.1x47-d10 (including)
JunosJuniper12.3 (including)12.3 (including)
JunosJuniper12.3-r1 (including)12.3-r1 (including)
JunosJuniper12.3-r2 (including)12.3-r2 (including)
JunosJuniper12.3-r3 (including)12.3-r3 (including)
JunosJuniper12.3-r4 (including)12.3-r4 (including)
JunosJuniper12.3-r5 (including)12.3-r5 (including)
JunosJuniper12.3-r6 (including)12.3-r6 (including)
JunosJuniper12.3-r7 (including)12.3-r7 (including)
JunosJuniper12.3-r8 (including)12.3-r8 (including)
JunosJuniper13.1 (including)13.1 (including)
JunosJuniper13.1-r1 (including)13.1-r1 (including)
JunosJuniper13.1-r2 (including)13.1-r2 (including)
JunosJuniper13.1-r3 (including)13.1-r3 (including)
JunosJuniper13.1-r4 (including)13.1-r4 (including)
JunosJuniper13.2 (including)13.2 (including)
JunosJuniper13.2-r1 (including)13.2-r1 (including)
JunosJuniper13.2-r2 (including)13.2-r2 (including)
JunosJuniper13.2-r3 (including)13.2-r3 (including)
JunosJuniper13.2-r4 (including)13.2-r4 (including)
JunosJuniper13.2-r5 (including)13.2-r5 (including)
JunosJuniper13.3 (including)13.3 (including)
JunosJuniper13.3-r1 (including)13.3-r1 (including)
JunosJuniper13.3-r2 (including)13.3-r2 (including)
JunosJuniper13.3-r3 (including)13.3-r3 (including)
JunosJuniper13.3-r4 (including)13.3-r4 (including)
JunosJuniper14.1 (including)14.1 (including)
JunosJuniper14.1-r1 (including)14.1-r1 (including)
JunosJuniper14.1-r2 (including)14.1-r2 (including)
JunosJuniper14.2 (including)14.2 (including)

References