← back
CVE-2015-7755

CVE-2015-7755

CVSS 9.8 CRITICALEPSS 61.4%● KEVCWE-287
In short

Juniper ScreenOS firewalls contain a critical flaw that allows attackers to gain full administrative access by entering a special password during SSH or Telnet connections. This vulnerability puts entire networks at risk because attackers can take complete control of the firewall.

Technical detail

CVE-2015-7755 is an authentication bypass in Juniper ScreenOS affecting versions 6.2.0r15-r18 and 6.3.0 series. Remote attackers can obtain administrative privileges via an undisclosed password during SSH or Telnet sessions (CWE-287: Improper Authentication). The attack requires network access to the management interface and results in complete administrative compromise of the device.

Summary generated and translated by AI from the official description.
Juniper ScreenOS 6.2.0r15 through 6.2.0r18, 6.3.0r12 before 6.3.0r12b, 6.3.0r13 before 6.3.0r13b, 6.3.0r14 before 6.3.0r14b, 6.3.0r15 before 6.3.0r15b, 6.3.0r16 before 6.3.0r16b, 6.3.0r17 before 6.3.0r17b, 6.3.0r18 before 6.3.0r18b, 6.3.0r19 before 6.3.0r19b, and 6.3.0r20 before 6.3.0r21 allows remote attackers to obtain administrative access by entering an unspecified password during a (1) SSH or (2) TELNET session.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →