CVE-2015-7755

9.5 CISA KEV

Juniper · ScreenOS

A critical authentication bypass in Juniper ScreenOS allows remote, unauthenticated attackers to gain administrative access via SSH or Telnet by providing a specific, hardcoded password.

Executive summary

Juniper ScreenOS is affected by a critical authentication bypass vulnerability that is currently being actively exploited in the wild to gain full administrative control over affected firewalls.

Vulnerability

This flaw involves unauthorized, hardcoded code within the operating system that permits any unauthenticated remote attacker to bypass authentication mechanisms during SSH or Telnet sessions. By entering a specific, undisclosed password, an attacker can achieve complete administrative access to the device.

Business impact

The compromise of a network firewall presents a catastrophic risk to organizational security, as it grants attackers the ability to intercept traffic, modify firewall rules, and gain a foothold into the internal network. Given the CVSS score of 9.5, this vulnerability is classified as critical, reflecting the ease of exploitation and the total loss of confidentiality, integrity, and availability. Unauthorized access to these devices can lead to large scale data exfiltration and complete loss of network visibility.

Remediation

Immediate Action: Update the affected Juniper ScreenOS devices to the patched versions: 6.2.0r19, 6.3.0r21, or the specific "b" suffix releases (6.3.0r12b, 6.3.0r13b, 6.3.0r14b, 6.3.0r15b, 6.3.0r16b, 6.3.0r17b, 6.3.0r18b, 6.3.0r19b).

Proactive Monitoring: Review firewall administrative access logs for unusual login attempts or connections originating from unauthorized IP addresses.

Compensating Controls: Disable Telnet and restrict SSH access to known, trusted management IP addresses to reduce the attack surface until the firmware patch is applied.

Exploitation status

Public Exploit Available: Yes, a public exploit is available via a Metasploit module and various documented proof-of-concept repositories.

Analyst recommendation

Due to the critical nature of this vulnerability and the confirmed active exploitation in the wild, immediate remediation is required. Administrators must prioritize patching these systems as they are primary targets for persistent threats looking to compromise network perimeters. If patching cannot be performed immediately, the device should be isolated from the network to prevent unauthorized access.

More Juniper CVEs

Sources