CVE-2025-13914
8.7Juniper Networks · Apstra
An insufficient SSH host key validation vulnerability in Juniper Networks Apstra allows an unauthenticated man-in-the-middle attacker to impersonate managed devices and capture credentials.
Executive summary
A critical authentication vulnerability in Juniper Networks Apstra allows unauthenticated attackers to perform man-in-the-middle attacks and compromise managed device credentials.
Vulnerability
This flaw involves a key exchange without entity authentication (CWE-322) caused by insufficient SSH host key validation. An unauthenticated attacker positioned as a man-in-the-middle can intercept SSH connections, impersonate managed devices, and capture sensitive user credentials.
Business impact
The ability for an unauthenticated attacker to impersonate managed devices poses a severe risk to network integrity and confidentiality. Successful exploitation could lead to the unauthorized interception of administrative credentials, facilitating further lateral movement within the infrastructure. With a CVSS score of 8.7, this high-severity vulnerability requires immediate attention to prevent potential unauthorized access to critical network management planes.
Remediation
Immediate Action: Upgrade Juniper Networks Apstra to version 6.1.1 or any subsequent release to address the host key validation flaw.
Proactive Monitoring: Monitor network traffic for anomalous SSH connection patterns and review authentication logs for signs of unauthorized device impersonation attempts.
Compensating Controls: Implement strict network segmentation to restrict access to the management interface and ensure that SSH connections to managed devices are performed over trusted, isolated management networks.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the potential for credential theft and device impersonation, organizations must prioritize upgrading their Apstra deployments to version 6.1.1. Verification of the patch installation is essential to ensure that SSH host key validation is correctly enforced across all managed device connections.
More Juniper Networks CVEs
Sources
Originally found and disclosed by Juniper SIRT would like to acknowledge and thank the Federal Office for Information Security (BSI) for responsibly repor, per the CVE Program record.