CVE-2014-3825: Juniper Junos
Medium severity, CVSS 6.8. EPSS: 2% chance of exploitation in the next 30 days.
The Juniper SRX Series devices with Junos 11.4 before 11.4R12-S4, 12.1X44 before 12.1X44-D40, 12.1X45 before 12.1X45-D30, 12.1X46 before 12.1X46-D25, and 12.1X47 before 12.1X47-D10, when an Application Layer Gateway (ALG) is enabled, allows remote attackers to cause a denial of service (flowd crash) via a crafted packet.
Affected products
- Juniper Junos: version 11.4 only; version 12.1 only; version 12.1x44 only; version 12.1x45 only; version 12.1x46 only; version 12.1x47 only
- Juniper SRX100
- Juniper SRX110
- Juniper SRX1400
- Juniper SRX210
- Juniper SRX220
- Juniper SRX240
- Juniper SRX3400
- Juniper SRX3600
- Juniper SRX550
- Juniper SRX5600
- Juniper SRX5800
- Juniper SRX650
Published 2014-10-14. Last modified 2026-06-17.