PT-2020-4096 · Juniper Networks · Nfx250 Network Services Platform

Published

2020-04-08

·

Updated

2020-07-29

·

CVE-2020-1614

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Juniper Networks NFX250 Network Services Platform vSRX VNF instance versions prior to 19.2R1
Description: A Use of Hard-coded Credentials issue exists in the NFX250 Series for the vSRX Virtual Network Function (VNF) instance. This allows an attacker to take control of the vSRX VNF instance if they have access to an administrative service, such as SSH, on the VNF, either locally or through the network. The issue only affects environments where the vSRX VNF root password has not been configured.
Recommendations: For versions prior to 19.2R1, update to version 19.2R1 or later to resolve the issue. As a temporary workaround, consider configuring the vSRX VNF root password to prevent exploitation. Restrict access to administrative services, such as SSH, to minimize the risk of unauthorized access.

Fix

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-04496
CVE-2020-1614

Affected Products

Nfx250 Network Services Platform