Unrated severityNVD Advisory· Published Jul 11, 2013· Updated Jun 16, 2026
CVE-2013-4685
CVE-2013-4685
Description
Buffer overflow in flowd in Juniper Junos 10.4 before 10.4S14, 11.4 before 11.4R7, 12.1 before 12.1R6, and 12.1X44 before 12.1X44-D15 on SRX devices, when Captive Portal is enabled with the UAC enforcer role, allows remote attackers to execute arbitrary code via crafted HTTP requests, aka PR 849100.
Affected products
17- cpe:2.3:h:juniper:srx100:-:*:*:*:*:*:*:*
- cpe:2.3:h:juniper:srx110:-:*:*:*:*:*:*:*
- cpe:2.3:h:juniper:srx1400:-:*:*:*:*:*:*:*
- cpe:2.3:h:juniper:srx210:-:*:*:*:*:*:*:*
- cpe:2.3:h:juniper:srx220:-:*:*:*:*:*:*:*
- cpe:2.3:h:juniper:srx240:-:*:*:*:*:*:*:*
- cpe:2.3:h:juniper:srx3400:-:*:*:*:*:*:*:*
- cpe:2.3:h:juniper:srx3600:-:*:*:*:*:*:*:*
- cpe:2.3:h:juniper:srx550:-:*:*:*:*:*:*:*
- cpe:2.3:h:juniper:srx5600:-:*:*:*:*:*:*:*
- cpe:2.3:h:juniper:srx5800:-:*:*:*:*:*:*:*
- cpe:2.3:h:juniper:srx650:-:*:*:*:*:*:*:*
cpe:2.3:o:juniper:junos:10.4:*:*:*:*:*:*:*+ 4 more
- cpe:2.3:o:juniper:junos:10.4:*:*:*:*:*:*:*
- cpe:2.3:o:juniper:junos:11.4:*:*:*:*:*:*:*
- cpe:2.3:o:juniper:junos:12.1:*:*:*:*:*:*:*
- cpe:2.3:o:juniper:junos:12.1x44:*:*:*:*:*:*:*
- (no CPE)range: 10.4 < 10.4S14, 11.4 < 11.4R7, 12.1 < 12.1R6, 12.1X44 < 12.1X44-D15
Patches
Vulnerability mechanics
References
3- kb.juniper.net/JSA10574nvdVendor Advisory
- osvdb.org/95108nvd
- www.securityfocus.com/bid/61125nvd
News mentions
0No linked articles in our index yet.