cSRX: Use of Hard-coded Cryptographic Keys allows an attacker to take control of the device through device management services.
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 8.1epss 0.9%
exploitation probability
0.9%top 44% of all CVEs
observed exploitation
nono source reports it
The use of multiple hard-coded cryptographic keys in cSRX Series software in Juniper Networks Junos OS allows an attacker to take control of any instance of a cSRX deployment through device management services. This issue affects: Juniper Networks Junos OS on cSRX Series: All versions prior to 20.2R3; 20.3 versions prior to 20.3R2; 20.4 versions prior to 20.4R2.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
Juniper Networks · Junos OSReferences
https://kb.juniper.net/JSA11157