CVE-2020-1615: Junos OS: vMX: Default credentials supplied in vMX configuration
The factory configuration for vMX installations, as shipped, includes default credentials for the root account. Without proper modification of these default credentials by the administrator, an attacker could exploit these credentials and access the vMX instance without authorization. This issue affects Juniper Networks Junos OS: 17.1 versions prior to 17.1R2-S11, 17.1R3-S2 on vMX; 17.2 versions prior to 17.2R3-S3 on vMX; 17.3 versions prior to 17.3R2-S5, 17.3R3-S7 on vMX; 17.4 versions prior to 17.4R2-S9, 17.4R3 on vMX; 18.1 versions prior to 18.1R3-S9 on vMX; 18.2 versions prior to 18.2R2-S7, 18.2R3-S3 on vMX; 18.2X75 versions prior to 18.2X75-D420, 18.2X75-D60 on vMX; 18.3 versions prior to 18.3R1-S7, 18.3R2-S3, 18.3R3-S1 on vMX; 18.4 versions prior to 18.4R1-S5, 18.4R2-S3, 18.4R3 on vMX; 19.1 versions prior to 19.1R1-S4, 19.1R2, 19.1R3 on vMX; 19.2 versions prior to 19.2R1-S3, 19.2R2 on vMX; 19.3 versions prior to 19.3R1-S1, 19.3R2 on vMX.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Junos OS (vMX)to a version that resolves this vulnerability.Fixed in 17.1R2-S11 - Upgrade
Upgrade
Junos OS (vMX)to a version that resolves this vulnerability.Fixed in 17.1R3-S2 - Upgrade
Upgrade
Junos OS (vMX)to a version that resolves this vulnerability.Fixed in 17.2R3-S3 - Upgrade
Upgrade
Junos OS (vMX)to a version that resolves this vulnerability.Fixed in 17.3R2-S5 - Upgrade
Upgrade
Junos OS (vMX)to a version that resolves this vulnerability.Fixed in 17.3R3-S7 - Upgrade
Upgrade
Junos OS (vMX)to a version that resolves this vulnerability.Fixed in 17.4R2-S9 - Upgrade
Upgrade
Junos OS (vMX)to a version that resolves this vulnerability.Fixed in 17.4R3 - Upgrade
Upgrade
Junos OS (vMX)to a version that resolves this vulnerability.Fixed in 18.1R3-S9 - Upgrade
Upgrade
Junos OS (vMX)to a version that resolves this vulnerability.Fixed in 18.2R2-S7 - Upgrade
Upgrade
Junos OS (vMX)to a version that resolves this vulnerability.Fixed in 18.2R3-S3 - Upgrade
Upgrade
Junos OS (vMX)to a version that resolves this vulnerability.Fixed in 18.2X75-D420 - Upgrade
Upgrade
Junos OS (vMX)to a version that resolves this vulnerability.Fixed in 18.2X75-D60 - Upgrade
Upgrade
Junos OS (vMX)to a version that resolves this vulnerability.Fixed in 18.3R1-S7 - Upgrade
Upgrade
Junos OS (vMX)to a version that resolves this vulnerability.Fixed in 18.3R2-S3 - Upgrade
Upgrade
Junos OS (vMX)to a version that resolves this vulnerability.Fixed in 18.3R3-S1 - Upgrade
Upgrade
Junos OS (vMX)to a version that resolves this vulnerability.Fixed in 18.4R1-S5 - Upgrade
Upgrade
Junos OS (vMX)to a version that resolves this vulnerability.Fixed in 18.4R2-S3 - Upgrade
Upgrade
Junos OS (vMX)to a version that resolves this vulnerability.Fixed in 18.4R3 - Upgrade
Upgrade
Junos OS (vMX)to a version that resolves this vulnerability.Fixed in 19.1R1-S4 - Upgrade
Upgrade
Junos OS (vMX)to a version that resolves this vulnerability.Fixed in 19.1R2 - Upgrade
Upgrade
Junos OS (vMX)to a version that resolves this vulnerability.Fixed in 19.1R3 - Upgrade
Upgrade
Junos OS (vMX)to a version that resolves this vulnerability.Fixed in 19.2R1-S3 - Upgrade
Upgrade
Junos OS (vMX)to a version that resolves this vulnerability.Fixed in 19.2R2 - Upgrade
Upgrade
Junos OS (vMX)to a version that resolves this vulnerability.Fixed in 19.3R1-S1 - Upgrade
Upgrade
Junos OS (vMX)to a version that resolves this vulnerability.Fixed in 19.3R2 - Upgrade
Upgrade
Junos OS (vMX)to a version that resolves this vulnerability.Fixed in 19.4R1 - Operational
Modify the factory default credentials for the root account on vMX installations (do not leave the factory-supplied default root credentials unchanged), so an attacker cannot exploit them to access the vMX instance without authorization.
Event History
Frequently Asked Questions
What is the severity of CVE-2020-1615?
CVE-2020-1615 has a high severity due to the inclusion of default credentials for the root account in vMX installations.
How do I fix CVE-2020-1615?
To fix CVE-2020-1615, it is essential to change the default root account credentials to secure passwords immediately after installation.
What versions of Juniper JUNOS are affected by CVE-2020-1615?
CVE-2020-1615 affects multiple versions of Juniper JUNOS, including 17.1, 17.2, 17.3, 17.4, and several sub-releases.
What is the impact of not addressing CVE-2020-1615?
Failing to address CVE-2020-1615 can allow unauthorized access to the vMX instance, potentially leading to data breaches or system compromises.
Are there any mitigations for CVE-2020-1615?
The primary mitigation for CVE-2020-1615 is to ensure that default root passwords are updated to unique and strong passwords.