Vulnerability Description
The use of multiple hard-coded cryptographic keys in cSRX Series software in Juniper Networks Junos OS allows an attacker to take control of any instance of a cSRX deployment through device management services. This issue affects: Juniper Networks Junos OS on cSRX Series: All versions prior to 20.2R3; 20.3 versions prior to 20.3R2; 20.4 versions prior to 20.4R2.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Juniper | Junos | 20.2 |
| Juniper | Csrx | - |
Related Weaknesses (CWE)
References
- https://kb.juniper.net/JSA11157Vendor Advisory
- https://kb.juniper.net/JSA11157Vendor Advisory
FAQ
What is CVE-2021-0266?
CVE-2021-0266 is a vulnerability with a CVSS score of 8.1 (HIGH). The use of multiple hard-coded cryptographic keys in cSRX Series software in Juniper Networks Junos OS allows an attacker to take control of any instance of a cSRX deployment through device management...
How severe is CVE-2021-0266?
CVE-2021-0266 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-0266?
Check the references section above for vendor advisories and patch information. Affected products include: Juniper Junos, Juniper Csrx.