CVE-2015-7755: Juniper ScreenOS Improper Authentication Vulnerability
Juniper ScreenOS 6.2.0r15 through 6.2.0r18, 6.3.0r12 before 6.3.0r12b, 6.3.0r13 before 6.3.0r13b, 6.3.0r14 before 6.3.0r14b, 6.3.0r15 before 6.3.0r15b, 6.3.0r16 before 6.3.0r16b, 6.3.0r17 before 6.3.0r17b, 6.3.0r18 before 6.3.0r18b, 6.3.0r19 before 6.3.0r19b, and 6.3.0r20 before 6.3.0r21 allows remote attackers to obtain administrative access by entering an unspecified password during a (1) SSH or (2) TELNET session.
Other sources
Juniper ScreenOS contains an improper authentication vulnerability that could allow unauthorized remote administrative access to the device.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Juniper ScreenOSto a version that resolves this vulnerability.Fixed in 6.3.0r12b - Upgrade
Upgrade
Juniper ScreenOSto a version that resolves this vulnerability.Fixed in 6.3.0r13b - Upgrade
Upgrade
Juniper ScreenOSto a version that resolves this vulnerability.Fixed in 6.3.0r14b - Upgrade
Upgrade
Juniper ScreenOSto a version that resolves this vulnerability.Fixed in 6.3.0r15b - Upgrade
Upgrade
Juniper ScreenOSto a version that resolves this vulnerability.Fixed in 6.3.0r16b - Upgrade
Upgrade
Juniper ScreenOSto a version that resolves this vulnerability.Fixed in 6.3.0r17b - Upgrade
Upgrade
Juniper ScreenOSto a version that resolves this vulnerability.Fixed in 6.3.0r18b - Upgrade
Upgrade
Juniper ScreenOSto a version that resolves this vulnerability.Fixed in 6.3.0r19b - Upgrade
Upgrade
Juniper ScreenOSto a version that resolves this vulnerability.Fixed in 6.3.0r21 - Compensating control
Follow applicable BOD 22-01 guidance for cloud services as referenced in the vendor advisory to mitigate exposure for affected Juniper/NetScreen ScreenOS instances.
- Operational
Discontinue use of the product if mitigations are unavailable.
Event History
Frequently Asked Questions
What is the severity of CVE-2015-7755?
CVE-2015-7755 is considered a high severity vulnerability due to its potential for unauthorized remote access.
How do I fix CVE-2015-7755?
To fix CVE-2015-7755, upgrade to ScreenOS versions 6.3.0r21 or later, or apply relevant patches provided by Juniper.
What systems are affected by CVE-2015-7755?
CVE-2015-7755 affects Juniper ScreenOS versions 6.2.0r15 through 6.3.0r20, specifically the specified releases.
What type of vulnerability is CVE-2015-7755?
CVE-2015-7755 is a vulnerability that allows unauthorized remote code execution on affected Juniper devices.
Is CVE-2015-7755 being actively exploited?
Yes, CVE-2015-7755 has been reported to be actively exploited in the wild, necessitating immediate remediation.