CVE-2024-30407: [Child CVE] JCNR and cRPD: Hard-coded SSH host keys in cRPD may allow Person-in-the-Middle (PitM) attacks
The Use of a Hard-coded Cryptographic Key vulnerability in Juniper Networks Juniper Cloud Native Router (JCNR) and containerized routing Protocol Deamon (cRPD) products allows an attacker to perform Person-in-the-Middle (PitM) attacks which results in complete compromise of the container.
Due to hardcoded SSH host keys being present on the container, a PitM attacker can intercept SSH traffic without being detected.
This issue affects Juniper Networks JCNR: All versions before 23.4.
This issue affects Juniper Networks cRPD: All versions before 23.4R1.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-30407?
The CVE-2024-30407 vulnerability is rated as critical due to its potential for allowing complete compromise of the affected products.
How do I fix CVE-2024-30407?
To mitigate CVE-2024-30407, update to a patched version of Juniper Cloud Native Router or containerized routing Protocol Deamon beyond version 23.4.
What products are affected by CVE-2024-30407?
CVE-2024-30407 affects Juniper Networks Juniper Cloud Native Router versions up to 23.4 and containerized routing Protocol Deamon versions up to 23.4R1.
What type of attack does CVE-2024-30407 enable?
CVE-2024-30407 allows attackers to perform Person-in-the-Middle (PitM) attacks.
What is the impact of CVE-2024-30407 on system security?
The impact of CVE-2024-30407 is a complete compromise of the confidentiality and integrity of the affected systems.