CVE-2025-11198: Security Director Policy Enforcer: An unrestricted API allows a network-based unauthenticated attacker to deploy malicious vSRX images to VMWare NSX Server
A Missing Authentication for Critical Function vulnerability in Juniper Networks Security Director Policy Enforcer allows an unauthenticated, network-based attacker to replace legitimate vSRX images with malicious ones.
If a trusted user initiates deployment, Security Director Policy Enforcer will deliver the attacker's uploaded image to VMware NSX instead of a legitimate one.
This issue affects Security Director Policy Enforcer:
All versions before 23.1R1 Hotpatch v3.
This issue does not affect Junos Space Security Director Insights.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Juniper Networks Security Director Policy Enforcerto a version that resolves this vulnerability.Fixed in 23.1R1 Hotpatch v3 - Operational
Rotate secrets across all devices after upgrading.
Event History
Frequently Asked Questions
What is the severity of CVE-2025-11198?
CVE-2025-11198 has a high severity rating as it allows unauthenticated attackers to replace legitimate vSRX images.
How do I fix CVE-2025-11198?
To fix CVE-2025-11198, ensure that all installations of Juniper Networks Security Director Policy Enforcer are updated to a secure version beyond 23.1R1 Hotpatch v3.
What types of attackers can exploit CVE-2025-11198?
CVE-2025-11198 can be exploited by unauthenticated, network-based attackers.
What impact does CVE-2025-11198 have on my system?
The impact of CVE-2025-11198 includes the ability for attackers to deploy malicious vSRX images, potentially compromising network security.
Is Juniper Networks Security Director Policy Enforcer the only affected software for CVE-2025-11198?
Yes, Juniper Networks Security Director Policy Enforcer is the primary affected software for CVE-2025-11198.