CVE-2015-7754: Input Validation
Published Jan 8, 2016
·Updated
Juniper ScreenOS before 6.3.0r21, when ssh-pka is configured and enabled, allows remote attackers to cause a denial of service (system crash) or execute arbitrary code via crafted SSH negotiation.
Affected Software
1 affected component
Juniper ScreenOS<=6.3.0
Event History
Jan 8, 2016
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-7754?
CVE-2015-7754 is classified as a critical vulnerability due to its potential to allow remote code execution and denial of service.
2
How do I fix CVE-2015-7754?
To fix CVE-2015-7754, upgrade Juniper ScreenOS to version 6.3.0r21 or later.
3
What systems are affected by CVE-2015-7754?
CVE-2015-7754 affects Juniper ScreenOS versions prior to 6.3.0r21 with ssh-pka configured and enabled.
4
What can attackers achieve through CVE-2015-7754?
Attackers can exploit CVE-2015-7754 to cause a denial of service or execute arbitrary code on the affected system.
5
Is there a workaround for CVE-2015-7754?
There are no official workarounds for CVE-2015-7754; the best course of action is to apply the necessary patch.