Buffer overflow in flowd in Juniper Junos 10.4 before 10.4S14, 11.4 before 11.4R7, 12.1 before 12.1R6, and 12.1X44 before 12.1X44-D15 on SRX devices, when Captive Portal is enabled with the UAC enforcer role, allows remote attackers to execute arbitrary code via crafted HTTP requests, aka PR 849100.
2013-07-11T14:55:01.350
2025-04-11T00:51:21.963
Deferred
CVSSv2: 10.0 (HIGH)
AV:N/AC:L/Au:N/C:C/I:C/A:C
10.0
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | juniper | junos | 10.4 | Yes |
Operating System | juniper | junos | 11.4 | Yes |
Operating System | juniper | junos | 12.1 | Yes |
Operating System | juniper | junos | 12.1x44 | Yes |
Hardware | juniper | srx100 | - | Yes |
Hardware | juniper | srx110 | - | Yes |
Hardware | juniper | srx1400 | - | Yes |
Hardware | juniper | srx210 | - | Yes |
Hardware | juniper | srx220 | - | Yes |
Hardware | juniper | srx240 | - | Yes |
Hardware | juniper | srx3400 | - | Yes |
Hardware | juniper | srx3600 | - | Yes |
Hardware | juniper | srx550 | - | Yes |
Hardware | juniper | srx5600 | - | Yes |
Hardware | juniper | srx5800 | - | Yes |
Hardware | juniper | srx650 | - | Yes |