Vulnerability Description
A Missing Authentication for Critical Function vulnerability in Juniper Networks Security Director Policy Enforcer allows an unauthenticated, network-based attacker to replace legitimate vSRX images with malicious ones. If a trusted user initiates deployment, Security Director Policy Enforcer will deliver the attacker's uploaded image to VMware NSX instead of a legitimate one. This issue affects Security Director Policy Enforcer: * All versions before 23.1R1 Hotpatch v3. This issue does not affect Junos Space Security Director Insights.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Juniper | Security Director Policy Enforcer | < 23.1 |
Related Weaknesses (CWE)
References
- https://supportportal.juniper.net/JSA103437Vendor Advisory
FAQ
What is CVE-2025-11198?
CVE-2025-11198 is a vulnerability with a CVSS score of 7.4 (HIGH). A Missing Authentication for Critical Function vulnerability in Juniper Networks Security Director Policy Enforcer allows an unauthenticated, network-based attacker to replace legitimate vSRX images w...
How severe is CVE-2025-11198?
CVE-2025-11198 has been rated HIGH with a CVSS base score of 7.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-11198?
Check the references section above for vendor advisories and patch information. Affected products include: Juniper Security Director Policy Enforcer.