CVE-2024-30407: critical vulnerability in Juniper Networks, Inc. cRPD
[Child CVE] JCNR and cRPD: Hard-coded SSH host keys in cRPD may allow Person-in-the-Middle (PitM) attacks
Published · Updated
No sign of exploitation. No public exploitation artifact known so far.
Juniper's cloud networking containers (JCNR and cRPD) contain the same SSH security keys in every installation. An attacker on the network can impersonate the container and intercept all SSH connections without being detected, gaining complete control.
CWE-321 (hard-coded cryptographic key) enables man-in-the-middle attacks against SSH connections to JCNR and cRPD containers. The attack vector requires network access to intercept SSH traffic; the presence of identical SSH host keys across deployments eliminates key-based authentication as a security control, allowing credential harvesting and container compromise.