CVE-2013-6014
Summary
| CVE | CVE-2013-6014 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2013-10-28 22:55:04 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Juniper Junos 10.4 before 10.4S15, 11.4 before 11.4R9, 11.4X27 before 11.4X27.44, 12.1 before 12.1R7, 12.1X44 before 12.1X44-D20, 12.1X45 before 12.1X45-D15, 12.2 before 12.2R6, 12.3 before 12.3R3, 13.1 before 13.1R3, and 13.2 before 13.2R1, when Proxy ARP is enabled on an unnumbered interface, allows remote attackers to perform ARP poisoning attacks and possibly obtain sensitive information via a crafted ARP message. |
Risk And Classification
Primary CVSS: v3.1 9.3 CRITICAL from [email protected]
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:H
Problem Types: CWE-200 | n/a
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Primary | 9.3 | CRITICAL | CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:H |
| 2.0 | [email protected] | Primary | 6.1 | AV:A/AC:L/Au:N/C:N/I:C/A:N |
CVSS v3.1 Breakdown
Attack Vector
AdjacentAttack Complexity
LowPrivileges Required
NoneUser Interaction
NoneScope
ChangedConfidentiality
HighIntegrity
NoneAvailability
HighCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:H
CVSS v2.0 Breakdown
Access Vector
AdjacentAccess Complexity
LowAuthentication
NoneConfidentiality
NoneIntegrity
CompleteAvailability
NoneAV:A/AC:L/Au:N/C:N/I:C/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Juniper | Junos | 10.4 | All | All | All |
| Operating System | Juniper | Junos | 11.4 | All | All | All |
| Operating System | Juniper | Junos | 11.4x27 | All | All | All |
| Operating System | Juniper | Junos | 12.1 | All | All | All |
| Operating System | Juniper | Junos | 12.1x44 | All | All | All |
| Operating System | Juniper | Junos | 12.1x45 | All | All | All |
| Operating System | Juniper | Junos | 12.2 | All | All | All |
| Operating System | Juniper | Junos | 12.3 | All | All | All |
| Operating System | Juniper | Junos | 13.1 | All | All | All |
| Operating System | Juniper | Junos | 13.2 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 2013-10 Security Bulletin: Junos: Security issue with Proxy ARP enabled on unnumbered interface (CVE-2013-6014) - Juniper Networks | af854a3a-2127-422b-91ae-364da2661108 | kb.juniper.net | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.