ID

VAR-201307-0479


CVE

CVE-2013-4690


TITLE

Juniper Networks SRX1400 , SRX3400 ,and SRX3600 Run on Junos Vulnerability in which important information is obtained

Trust: 0.8

sources: JVNDB: JVNDB-2013-003336

DESCRIPTION

Juniper Junos 10.4 before 10.4S13, 11.4 before 11.4R7-S1, 12.1 before 12.1R5-S3, 12.1X44 before 12.1X44-D20, and 12.1X45 before 12.1X45-D10 on the SRX1400, SRX3400, and SRX3600 does not properly initialize memory locations used during padding of Ethernet packets, which allows remote attackers to obtain sensitive information by reading packet data, aka PR 829536, a related issue to CVE-2003-0001. Vendors have confirmed this vulnerability PR 829536 It is released as. This vulnerability CVE-2003-0001 And related issues.By reading the packet data by a third party, important information may be obtained. Multiple Juniper Gateway Products are prone to an information-disclosure vulnerability. Attackers can leverage this issue to gain access to sensitive information. Information obtained will aid in further attacks. Juniper Gateway Products SRX1400, SRX3400, and SRX3600 are vulnerable. Juniper Networks Juniper Junos is a set of network operating system of Juniper Networks (Juniper Networks) dedicated to the company's hardware system. The operating system provides a secure programming interface and Junos SDK

Trust: 2.07

sources: NVD: CVE-2013-4690 // JVNDB: JVNDB-2013-003336 // BID: 61123 // VULHUB: VHN-64692 // VULMON: CVE-2013-4690

AFFECTED PRODUCTS

vendor:junipermodel:junosscope:eqversion:12.1x44

Trust: 1.9

vendor:junipermodel:junosscope:eqversion:12.1

Trust: 1.9

vendor:junipermodel:junosscope:eqversion:11.4

Trust: 1.9

vendor:junipermodel:junosscope:eqversion:10.4

Trust: 1.9

vendor:junipermodel:junosscope:eqversion:12.1x45

Trust: 1.6

vendor:junipermodel:srx1400scope:eqversion: -

Trust: 1.0

vendor:junipermodel:srx3600scope:eqversion: -

Trust: 1.0

vendor:junipermodel:srx3400scope:eqversion: -

Trust: 1.0

vendor:junipermodel:junos osscope:ltversion:12.1x45

Trust: 0.8

vendor:junipermodel:srx1400scope: - version: -

Trust: 0.8

vendor:junipermodel:junos osscope:eqversion:11.4r7-s1

Trust: 0.8

vendor:junipermodel:junos osscope:eqversion:12.1x45-d10

Trust: 0.8

vendor:junipermodel:junos osscope:eqversion:10.4s13

Trust: 0.8

vendor:junipermodel:junos osscope:ltversion:10.4

Trust: 0.8

vendor:junipermodel:junos osscope:ltversion:12.1x44

Trust: 0.8

vendor:junipermodel:junos osscope:ltversion:12.1

Trust: 0.8

vendor:junipermodel:srx3400scope: - version: -

Trust: 0.8

vendor:junipermodel:junos osscope:eqversion:12.1r5-s3

Trust: 0.8

vendor:junipermodel:srx3600scope: - version: -

Trust: 0.8

vendor:junipermodel:junos osscope:eqversion:12.1x44-d20

Trust: 0.8

vendor:junipermodel:junos osscope:ltversion:11.4

Trust: 0.8

vendor:junipermodel:srx3600scope:eqversion:0

Trust: 0.3

vendor:junipermodel:srx3400scope:eqversion:0

Trust: 0.3

vendor:junipermodel:srx1400scope:eqversion:0

Trust: 0.3

vendor:junipermodel:junos 12.1x45-d10scope:neversion: -

Trust: 0.3

vendor:junipermodel:junos 12.1x44-d20scope:neversion: -

Trust: 0.3

vendor:junipermodel:junos 12.1r7scope:neversion: -

Trust: 0.3

vendor:junipermodel:junos 12.1r5-s3scope:neversion: -

Trust: 0.3

vendor:junipermodel:junos 11.4r8scope:neversion: -

Trust: 0.3

vendor:junipermodel:junos 11.4r7-s1scope:neversion: -

Trust: 0.3

vendor:junipermodel:junos 10.4s13scope:neversion: -

Trust: 0.3

vendor:junipermodel:junos 10.4r14scope:neversion: -

Trust: 0.3

sources: BID: 61123 // JVNDB: JVNDB-2013-003336 // CNNVD: CNNVD-201307-233 // NVD: CVE-2013-4690

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2013-4690
value: MEDIUM

Trust: 1.0

NVD: CVE-2013-4690
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-201307-233
value: MEDIUM

Trust: 0.6

VULHUB: VHN-64692
value: MEDIUM

Trust: 0.1

VULMON: CVE-2013-4690
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2013-4690
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.9

VULHUB: VHN-64692
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-64692 // VULMON: CVE-2013-4690 // JVNDB: JVNDB-2013-003336 // CNNVD: CNNVD-201307-233 // NVD: CVE-2013-4690

PROBLEMTYPE DATA

problemtype:CWE-399

Trust: 1.9

sources: VULHUB: VHN-64692 // JVNDB: JVNDB-2013-003336 // NVD: CVE-2013-4690

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201307-233

TYPE

resource management error

Trust: 0.6

sources: CNNVD: CNNVD-201307-233

CONFIGURATIONS

sources: JVNDB: JVNDB-2013-003336

PATCH

title:JSA10579url:http://kb.juniper.net/JSA10579

Trust: 0.8

sources: JVNDB: JVNDB-2013-003336

EXTERNAL IDS

db:NVDid:CVE-2013-4690

Trust: 2.9

db:JUNIPERid:JSA10579

Trust: 2.1

db:BIDid:61123

Trust: 1.5

db:OSVDBid:95112

Trust: 1.2

db:JVNDBid:JVNDB-2013-003336

Trust: 0.8

db:CNNVDid:CNNVD-201307-233

Trust: 0.7

db:VULHUBid:VHN-64692

Trust: 0.1

db:VULMONid:CVE-2013-4690

Trust: 0.1

sources: VULHUB: VHN-64692 // VULMON: CVE-2013-4690 // BID: 61123 // JVNDB: JVNDB-2013-003336 // CNNVD: CNNVD-201307-233 // NVD: CVE-2013-4690

REFERENCES

url:http://kb.juniper.net/jsa10579

Trust: 1.8

url:http://www.securityfocus.com/bid/61123

Trust: 1.3

url:http://osvdb.org/95112

Trust: 1.2

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/85627

Trust: 1.2

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2013-4690

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2013-4690

Trust: 0.8

url:http://www.juniper.net/

Trust: 0.3

url:http://kb.juniper.net/infocenter/index?page=content&id=jsa10579

Trust: 0.3

url:https://cwe.mitre.org/data/definitions/399.html

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

sources: VULHUB: VHN-64692 // VULMON: CVE-2013-4690 // BID: 61123 // JVNDB: JVNDB-2013-003336 // CNNVD: CNNVD-201307-233 // NVD: CVE-2013-4690

CREDITS

Juniper Networks

Trust: 0.3

sources: BID: 61123

SOURCES

db:VULHUBid:VHN-64692
db:VULMONid:CVE-2013-4690
db:BIDid:61123
db:JVNDBid:JVNDB-2013-003336
db:CNNVDid:CNNVD-201307-233
db:NVDid:CVE-2013-4690

LAST UPDATE DATE

2024-11-23T23:12:49.283000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-64692date:2017-08-29T00:00:00
db:VULMONid:CVE-2013-4690date:2017-08-29T00:00:00
db:BIDid:61123date:2013-07-11T00:00:00
db:JVNDBid:JVNDB-2013-003336date:2013-07-16T00:00:00
db:CNNVDid:CNNVD-201307-233date:2013-07-19T00:00:00
db:NVDid:CVE-2013-4690date:2024-11-21T01:56:04.440

SOURCES RELEASE DATE

db:VULHUBid:VHN-64692date:2013-07-11T00:00:00
db:VULMONid:CVE-2013-4690date:2013-07-11T00:00:00
db:BIDid:61123date:2013-07-11T00:00:00
db:JVNDBid:JVNDB-2013-003336date:2013-07-16T00:00:00
db:CNNVDid:CNNVD-201307-233date:2013-07-12T00:00:00
db:NVDid:CVE-2013-4690date:2013-07-11T14:55:01.423