PT-2021-19253 · Juniper Networks · Juniper Networks Src Series

Published

2021-10-19

·

Updated

2022-10-27

·

CVE-2021-31352

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Juniper Networks SRC Series versions prior to 4.13.0-R6
Description An Information Exposure issue in Juniper Networks SRC Series devices configured for NETCONF over SSH allows the negotiation of weak ciphers. This could enable a remote attacker to obtain sensitive information by exploiting the vulnerability to display plaintext bits from a block of ciphertext.
Recommendations For Juniper Networks SRC Series versions prior to 4.13.0-R6, update to version 4.13.0-R6 or later to resolve the issue.

Exploit

Fix

Information Disclosure

Use of a Broken Cryptographic Algorithm

Weakness Enumeration

Related Identifiers

CVE-2021-31352

Affected Products

Juniper Networks Src Series