CVE-2014-6382: Juniper Junos

High severity, CVSS 7.1. EPSS: 1.2% chance of exploitation in the next 30 days.

The Juniper MX Series routers with Junos 13.3R3 through 13.3Rx before 13.3R6, 14.1 before 14.1R4, 14.1X50 before 14.1X50-D70, and 14.2 before 14.2R2, when configured as a broadband edge (BBE) router, allows remote attackers to cause a denial of service (jpppd crash and restart) by sending a crafted PAP Authenticate-Request after the PPPoE Discovery and LCP phase are complete.

Affected products

  • Juniper Junos: version 13.3 only; version 14.1 only; version 14.2 only

Published 2015-01-16. Last modified 2026-06-17.