CVE-2021-0266: cSRX: Use of Hard-coded Cryptographic Keys allows an attacker to take control of the device through device management services.
The use of multiple hard-coded cryptographic keys in cSRX Series software in Juniper Networks Junos OS allows an attacker to take control of any instance of a cSRX deployment through device management services. This issue affects: Juniper Networks Junos OS on cSRX Series: All versions prior to 20.2R3; 20.3 versions prior to 20.3R2; 20.4 versions prior to 20.4R2.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2021-0266?
CVE-2021-0266 refers to a vulnerability in cSRX Series software in Juniper Networks Junos OS that allows an attacker to take control of any instance of a cSRX deployment through device management services.
Which versions of Juniper Networks Junos OS are affected by CVE-2021-0266?
CVE-2021-0266 affects all versions of Juniper Networks Junos OS on cSRX Series prior to 20.2R...
What is the severity of CVE-2021-0266?
The severity of CVE-2021-0266 is rated as critical, with a severity value of 9.8.
How can an attacker exploit CVE-2021-0266?
An attacker can exploit CVE-2021-0266 by taking advantage of the multiple hard-coded cryptographic keys in the cSRX Series software.
Is Juniper Csrx affected by CVE-2021-0266?
No, Juniper Csrx is not affected by CVE-2021-0266.