The use of multiple hard-coded cryptographic keys in cSRX Series software in Juniper Networks Junos OS allows an attacker to take control of any instance of a cSRX deployment through device management services. This issue affects: Juniper Networks Junos OS on cSRX Series: All versions prior to 20.2R3; 20.3 versions prior to 20.3R2; 20.4 versions prior to 20.4R2.
2021-04-22T20:15:09.877
2024-11-21T05:42:21.447
Modified
CVSSv3.1: 8.1 (HIGH)
AV:N/AC:L/Au:N/C:P/I:P/A:P
10.0
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | juniper | junos | 20.2 | Yes |
Operating System | juniper | junos | 20.2 | Yes |
Operating System | juniper | junos | 20.2 | Yes |
Operating System | juniper | junos | 20.2 | Yes |
Operating System | juniper | junos | 20.3 | Yes |
Operating System | juniper | junos | 20.3 | Yes |
Operating System | juniper | junos | 20.4 | Yes |
Operating System | juniper | junos | 20.4 | Yes |
Hardware | juniper | csrx | - | No |