CVE-2014-6382 describes a denial-of-service vulnerability affecting Juniper MX Series routers running specific Junos versions (13.3R3-13.3R6, 14.1, 14.1X50, 14.2) when configured as a broadband edge router. An unauthenticated remote attacker can crash the jpppd process, leading to a service restart, by sending a malformed PAP Authenticate-Request after the PPPoE and LCP phases. This vulnerability has a CVSS score of 7.1, indicating high severity due to its network-based attack vector, medium attack complexity, and complete denial-of-service impact. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
13.3CPE matchmatch criteria | cpe:2.3:o:juniper:junos:13.3:r3:*:*:*:*:*:* | ||
13.3CPE matchmatch criteria | cpe:2.3:o:juniper:junos:13.3:r4:*:*:*:*:*:* | ||
13.3CPE matchmatch criteria | cpe:2.3:o:juniper:junos:13.3:r5:*:*:*:*:*:* | ||
14.1CPE matchmatch criteria | cpe:2.3:o:juniper:junos:14.1:*:*:*:*:*:*:* | ||
14.1CPE matchmatch criteria | cpe:2.3:o:juniper:junos:14.1:r1:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:N/I:N/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.