PT-2025-29239 · Juniper Networks · Juniper Networks Security Director

Published

2025-07-09

·

Updated

2025-07-11

·

CVE-2025-52950

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Juniper Networks Security Director version 24.4.1
Description: A missing authorization vulnerability in Juniper Networks Security Director allows an unauthenticated network-based attacker to read or tamper with multiple sensitive resources via the web interface. Numerous endpoints on the Juniper Security Director appliance do not validate authorization, delivering information to the caller outside their authorization level. An attacker can access data beyond their authorized level, potentially gaining access to additional information or perpetrating further attacks, impacting downstream managed devices.
Recommendations: Versions prior to 24.4.1 are affected. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authorization

Weakness Enumeration

Related Identifiers

BDU:2025-08747
CVE-2025-52950

Affected Products

Juniper Networks Security Director