Vulnerability Description
Juniper ScreenOS 6.2.0r15 through 6.2.0r18, 6.3.0r12 before 6.3.0r12b, 6.3.0r13 before 6.3.0r13b, 6.3.0r14 before 6.3.0r14b, 6.3.0r15 before 6.3.0r15b, 6.3.0r16 before 6.3.0r16b, 6.3.0r17 before 6.3.0r17b, 6.3.0r18 before 6.3.0r18b, 6.3.0r19 before 6.3.0r19b, and 6.3.0r20 before 6.3.0r21 allows remote attackers to obtain administrative access by entering an unspecified password during a (1) SSH or (2) TELNET session.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Juniper | Screenos | 6.3.0 |
Related Weaknesses (CWE)
References
- http://arstechnica.com/security/2015/12/unauthorized-code-in-juniper-firewalls-dThird Party Advisory
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10713ExploitVendor Advisory
- http://twitter.com/cryptoron/statuses/677900647560253442Broken Link
- http://www.forbes.com/sites/thomasbrewster/2015/12/18/juniper-says-it-didnt-workPermissions Required
- http://www.kb.cert.org/vuls/id/640184Third Party Advisory
- http://www.securityfocus.com/bid/79626Broken Link
- http://www.securitytracker.com/id/1034489Broken Link
- http://www.wired.com/2015/12/juniper-networks-hidden-backdoors-show-the-risk-of-Third Party Advisory
- https://adamcaudill.com/2015/12/17/much-ado-about-juniper/Third Party Advisory
- https://forums.juniper.net/t5/Security-Incident-Response/Important-Announcement-Vendor Advisory
- https://github.com/hdm/juniper-cve-2015-7755Third Party Advisory
- http://arstechnica.com/security/2015/12/unauthorized-code-in-juniper-firewalls-dThird Party Advisory
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10713ExploitVendor Advisory
- http://twitter.com/cryptoron/statuses/677900647560253442Broken Link
- http://www.forbes.com/sites/thomasbrewster/2015/12/18/juniper-says-it-didnt-workPermissions Required
FAQ
What is CVE-2015-7755?
CVE-2015-7755 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Juniper ScreenOS 6.2.0r15 through 6.2.0r18, 6.3.0r12 before 6.3.0r12b, 6.3.0r13 before 6.3.0r13b, 6.3.0r14 before 6.3.0r14b, 6.3.0r15 before 6.3.0r15b, 6.3.0r16 before 6.3.0r16b, 6.3.0r17 before 6.3.0...
How severe is CVE-2015-7755?
CVE-2015-7755 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2015-7755?
Check the references section above for vendor advisories and patch information. Affected products include: Juniper Screenos.