CVE-2013-6014
Status: ModifiedCritical (9.3)—
Juniper Junos 10.4 before 10.4S15, 11.4 before 11.4R9, 11.4X27 before 11.4X27.44, 12.1 before 12.1R7, 12.1X44 before 12.1X44-D20, 12.1X45 before 12.1X45-D15, 12.2 before 12.2R6, 12.3 before 12.3R3, 13.1 before 13.1R3, and 13.2 before 13.2R1, when Proxy ARP is enabled on an unnumbered interface, allows remote attackers to perform ARP poisoning attacks and possibly obtain sensitive information via a crafted ARP message.
CVSS
- Version: 3.1
- Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:H
- Base score: 9.3
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 0.78%
- Percentile among all scored CVEs: 55
- Score date: 10/8/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
CWEs
- CWE-200
References
Raw JSON (NVD)
Show
{
"id": "CVE-2013-6014",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 6.1,
"accessVector": "ADJACENT_NETWORK",
"vectorString": "AV:A/AC:L/Au:N/C:N/I:C/A:N",
"authentication": "NONE",
"integrityImpact": "COMPLETE",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 6.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 6.5,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 9.3,
"attackVector": "ADJACENT_NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.8,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2013-10-28T22:55:04.133",
"references": [
{
"url": "https://kb.juniper.net/InfoCenter/index?page=content&id=JSA10595",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://kb.juniper.net/InfoCenter/index?page=content&id=JSA10595",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-200"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Juniper Junos 10.4 before 10.4S15, 11.4 before 11.4R9, 11.4X27 before 11.4X27.44, 12.1 before 12.1R7, 12.1X44 before 12.1X44-D20, 12.1X45 before 12.1X45-D15, 12.2 before 12.2R6, 12.3 before 12.3R3, 13.1 before 13.1R3, and 13.2 before 13.2R1, when Proxy ARP is enabled on an unnumbered interface, allows remote attackers to perform ARP poisoning attacks and possibly obtain sensitive information via a crafted ARP message."
},
{
"lang": "es",
"value": "Juniper Junos 10.4 anterior a 10.4S15, 11.4 anterior a 11.4R9, 11.4X27 anterior a 11.4X27.44, 12.1 anterior a 12.1R7, 12.1X44 anterior a 12.1X44-D20, 12.1X45 anterior a 12.1X45-D15, 12.2 anterior a 12.2R6, 12.3 anterior a 12.3R3, 13.1 anterior a 13.1R3, y 13.2 anterior a 13.2R1, cuando Proxy ARP está activo en una interfaz sin numerar, permite a atacantes remotos ejecutar envenenamiento ARP y posiblemente obtener información sensible a través de un mensaje ARP manipulado."
}
],
"lastModified": "2026-06-16T23:59:53.477",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:juniper:junos:10.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "45C2DA1E-12A7-4018-92CE-7621FC278025"
},
{
"criteria": "cpe:2.3:o:juniper:junos:11.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "41543223-0FA9-4CBE-8DEC-717CE5FFED79"
},
{
"criteria": "cpe:2.3:o:juniper:junos:11.4x27:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "80EFC6D6-43F9-4277-ACAC-D5929AF6FF7D"
},
{
"criteria": "cpe:2.3:o:juniper:junos:12.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B40B8FD6-A597-4845-8E8E-63EFDF606006"
},
{
"criteria": "cpe:2.3:o:juniper:junos:12.1x44:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1B307477-C5F2-4D98-AF4C-640D326164C7"
},
{
"criteria": "cpe:2.3:o:juniper:junos:12.1x45:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8E747970-4C27-4B46-9163-964252CB98F6"
},
{
"criteria": "cpe:2.3:o:juniper:junos:12.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5FB9541A-2570-459A-87D6-5341C67B8EC8"
},
{
"criteria": "cpe:2.3:o:juniper:junos:12.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8E014A0D-0054-4EBA-BA1F-035B74BD822F"
},
{
"criteria": "cpe:2.3:o:juniper:junos:13.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "71FB12AC-DB5A-444A-81E0-C0DDD06810EB"
},
{
"criteria": "cpe:2.3:o:juniper:junos:13.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CAB7D840-9469-4CE2-8DBF-017A44741374"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}