CVE-2015-7755
published 2015-12-19CVE-2015-7755: Juniper ScreenOS 6.2.0r15 through 6.2.0r18, 6.3.0r12 before 6.3.0r12b, 6.3.0r13 before 6.3.0r13b, 6.3.0r14 before 6.3.0r14b, 6.3.0r15 before 6.3.0r15b…
PriorityP196critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2025-10-23
Exploited in the wild
EPSS
61.40%
99.1th percentile
Juniper ScreenOS 6.2.0r15 through 6.2.0r18, 6.3.0r12 before 6.3.0r12b, 6.3.0r13 before 6.3.0r13b, 6.3.0r14 before 6.3.0r14b, 6.3.0r15 before 6.3.0r15b, 6.3.0r16 before 6.3.0r16b, 6.3.0r17 before 6.3.0r17b, 6.3.0r18 before 6.3.0r18b, 6.3.0r19 before 6.3.0r19b, and 6.3.0r20 before 6.3.0r21 allows remote attackers to obtain administrative access by entering an unspecified password during a (1) SSH or (2) TELNET session.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| juniper | screenos | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Scan for Juniper ScreenOS devices accepting the hardcoded backdoor password '<<< %s(un='%s') = %u' on SSH or Telnet; any username is valid with this password. ↗
- →Alert on successful SSH or Telnet administrative logins to Juniper ScreenOS 6.2.0r15–6.2.0r18 or 6.3.0r12–6.3.0r20 from unexpected sources, as the backdoor grants access with any username and the magic password. ↗
- ·The backdoor is valid on both SSH and Telnet sessions; any username combined with the magic password string grants administrative access — authentication bypass is not protocol-specific. ↗
- ·Affected versions span ScreenOS 6.2.0r15–6.2.0r18 and 6.3.0r12–6.3.0r20; patched versions include 6.3.0r12b, 6.3.0r13b through 6.3.0r19b, and 6.3.0r21. ↗
- ·CISA KEV classifies this as an improper authentication vulnerability enabling unauthorized remote administrative access; vendor mitigations must be applied or the product discontinued. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vulncheck9.8CRITICAL
cisa9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Juniper ScreenOS up to 6.2.0r18/6.3.0r20 SSH/Telnet Username improper authentication (JSA10713 / VU#640184)
vuldb·2026-04-23·CVSS 9.8
CVE-2015-7755 [CRITICAL] Juniper ScreenOS up to 6.2.0r18/6.3.0r20 SSH/Telnet Username improper authentication (JSA10713 / VU#640184)
A vulnerability described as critical has been identified in Juniper ScreenOS up to 6.2.0r18/6.3.0r20. Impacted is an unknown function of the component SSH/Telnet. The manipulation of the argument Username with the input username1/username2 results in improper authentication.
This vulnerability is cataloged as CVE-2015-7755. The attack may be launched remotely. Furthermore, there is an exploit available.
Upgrading the affected component is recommended.
VulDB
Juniper ScreenOS up to 6.2.0r18/6.3.0r20 VPN improper authentication (JSA10713 / VU#640184)
vuldb·2026-04-23·CVSS 9.8
CVE-2015-7755 [CRITICAL] Juniper ScreenOS up to 6.2.0r18/6.3.0r20 VPN improper authentication (JSA10713 / VU#640184)
A vulnerability classified as critical has been found in Juniper ScreenOS up to 6.2.0r18/6.3.0r20. The affected element is an unknown function of the component VPN. This manipulation causes improper authentication.
This vulnerability is registered as CVE-2015-7755. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
It is recommended to upgrade the affected component.
GHSA
GHSA-43vr-5w6h-pr3g: Juniper ScreenOS 6
ghsa_unreviewed·2022-05-17
CVE-2015-7755 [HIGH] CWE-287 GHSA-43vr-5w6h-pr3g: Juniper ScreenOS 6
Juniper ScreenOS 6.2.0r15 through 6.2.0r18, 6.3.0r12 before 6.3.0r12b, 6.3.0r13 before 6.3.0r13b, 6.3.0r14 before 6.3.0r14b, 6.3.0r15 before 6.3.0r15b, 6.3.0r16 before 6.3.0r16b, 6.3.0r17 before 6.3.0r17b, 6.3.0r18 before 6.3.0r18b, 6.3.0r19 before 6.3.0r19b, and 6.3.0r20 before 6.3.0r21 allows remote attackers to obtain administrative access by entering an unspecified password during a (1) SSH or (2) TELNET session.
VulnCheck
Juniper ScreenOS Improper Authentication Vulnerability
vulncheck·2015·CVSS 9.8
CVE-2015-7755 [CRITICAL] CWE-287 Juniper ScreenOS Improper Authentication Vulnerability
Juniper ScreenOS Improper Authentication Vulnerability
Juniper ScreenOS contains an improper authentication vulnerability that could allow unauthorized remote administrative access to the device.
Affected: Juniper ScreenOS
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Exploitation References: https://securityaffairs.com/42983/hacking/juniper-backdoor-attacks-honeypot.html; https://www.tripwire.com/state-of-security/doubledoor-iot-botnet-abuses-two-vulnerabilities-to-circumvent-firewalls-modems; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://cyble.com/resources/research-reports/global-cybersecurity-report/;
CISA
Juniper ScreenOS Improper Authentication Vulnerability
cisa·2025-10-02·CVSS 9.8
CVE-2015-7755 [CRITICAL] CWE-287 Juniper ScreenOS Improper Authentication Vulnerability
Vulnerability: Juniper ScreenOS Improper Authentication Vulnerability
Affected: Juniper ScreenOS
Juniper ScreenOS contains an improper authentication vulnerability that could allow unauthorized remote administrative access to the device.
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Notes: https://supportportal.juniper.net/s/article/2015-12-Out-of-Cycle-Security-Bulletin-ScreenOS-Multiple-Security-issues-with-ScreenOS-CVE-2015-7755-CVE-2015-7756 ; https://nvd.nist.gov/vuln/detail/CVE-2015-7755
Remediation Due Date: 2025-10-23
Juniper
CVE-2015-7755: Juniper ScreenOS 6.2.0r15 through 6.2.0r18, 6.3.0r12 before 6.3.0r12b, 6.3.0r13 before 6.3.0r13b, 6.3.0r14 before 6.3.0r14b, 6.3.0r15 before 6.3.0r15b
vendor_juniper·2015-12-19·CVSS 9.8
CVE-2015-7755 [CRITICAL] CWE-287 CVE-2015-7755: Juniper ScreenOS 6.2.0r15 through 6.2.0r18, 6.3.0r12 before 6.3.0r12b, 6.3.0r13 before 6.3.0r13b, 6.3.0r14 before 6.3.0r14b, 6.3.0r15 before 6.3.0r15b
CVE-2015-7755: Juniper ScreenOS 6.2.0r15 through 6.2.0r18, 6.3.0r12 before 6.3.0r12b, 6.3.0r13 before 6.3.0r13b, 6.3.0r14 before 6.3.0r14b, 6.3.0r15 before 6.3.0r15b, 6.3.0r16 before 6.3.0r16b, 6.3.0r17 before 6.3.0r17b, 6.3.0r18 before 6.3.0r18b, 6.3.0r19 before 6.3.0r19b, and 6.3.0r20 before 6.3.0r21 allows remote attackers to obtain administrative access by entering an unspecified password during a (1) SSH or (2) TELNET session.
CISA KEV: Juniper ScreenOS contains an improper authentication vulnerability that could allow unauthorized remote administrative access to the device.
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Suricata
ET INFO FOX-SRT - Juniper ScreenOS SSH World Reachable
suricata·2015-12-22
CVE-2015-7755 ET INFO FOX-SRT - Juniper ScreenOS SSH World Reachable
ET INFO FOX-SRT - Juniper ScreenOS SSH World Reachable
Rule: alert tcp $HOME_NET 22 -> $EXTERNAL_NET any (msg:"ET INFO FOX-SRT - Juniper ScreenOS SSH World Reachable"; flow:established,to_client; content:"SSH-2.0-NetScreen"; reference:cve,2015-7755; reference:url,kb.juniper.net/JSA10713; classtype:policy-violation; sid:2022299; rev:3; metadata:created_at 2015_12_22, cve CVE_2015_7755, confidence High, signature_severity Informational, updated_at 2024_03_07;)
Suricata
ET EXPLOIT Juniper ScreenOS telnet Backdoor Default Password Attempt
suricata·2015-12-21
CVE-2015-7755 ET EXPLOIT Juniper ScreenOS telnet Backdoor Default Password Attempt
ET EXPLOIT Juniper ScreenOS telnet Backdoor Default Password Attempt
Rule: alert tcp any any -> $HOME_NET 23 (msg:"ET EXPLOIT Juniper ScreenOS telnet Backdoor Default Password Attempt"; flow:established,to_server; content:"|3c 3c 3c 20 25 73 28 75 6e 3d 27 25 73 27 29 20 3d 20 25 75|"; fast_pattern; threshold: type limit, count 1, seconds 60, track by_src; reference:cve,2015-7755; reference:url,community.rapid7.com/community/infosec/blog/2015/12/20/cve-2015-7755-juniper-screenos-authentication-backdoor; classtype:attempted-admin; sid:2022291; rev:1; metadata:created_at 2015_12_21, cve CVE_2015_7755, confidence High, signature_severity Major, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2019_07_26;)
Krebs
Researchers Find Fresh Fodder for IoT Attack Cannons
blogs_krebs·2016-12-06·CVSS 9.8
[CRITICAL] Researchers Find Fresh Fodder for IoT Attack Cannons
New research published this week could provide plenty of fresh fodder for Mirai, a malware strain that enslaves poorly-secured Internet of Things (IoT) devices for use in powerful online attacks. Researchers in Austria have unearthed a pair of backdoor accounts in more than 80 different IP camera models made by Sony Corp. Separately, Israeli security experts have discovered trivially exploitable weaknesses in nearly a half-million white-labeled IP camera models that are not currently sought out by Mirai.
In a blog post published today, Austrian security firm SEC Consult said it found two apparent backdoor accounts in Sony IPELA Engine IP Cameras — devices mainly used by enterprises and authorities. According to SEC Consult, the two previously undocumented user accounts — named “primana” a
Krebs
Researchers Find Fresh Fodder for IoT Attack Cannons – Krebs on Security
blogs_krebs·2016-12-01·CVSS 9.8
[CRITICAL] Researchers Find Fresh Fodder for IoT Attack Cannons – Krebs on Security
New research published this week could provide plenty of fresh fodder for Mirai , a malware strain that enslaves poorly-secured Internet of Things (IoT) devices for use in powerful online attacks . Researchers in Austria have unearthed a pair of backdoor accounts in more than 80 different IP camera models made by Sony Corp . Separately, Israeli security experts have discovered trivially exploitable weaknesses in nearly a half-million white-labeled IP camera models that are not currently sought out by Mirai.
A Sony IPELA camera. Image: Sony.
In a blog post published today, Austrian security firm SEC Consult said it found two apparent backdoor accounts in Sony IPELA Engine IP Cameras — devices mainly used by enterprises and authorities. According to SEC Consult, the two previously undocume
Securelist
Threat intelligence report for the telecommunications industry
blogs_securelist·2016-08-22
Threat intelligence report for the telecommunications industry
Table of Contents
Introduction
Executive summary
Typical threats targeting telecoms
Overview
Threats directed at telecoms companies
DDoS
Targeted attacks
Unaddressed software vulnerabilities
The impact of service misconfiguration
Vulnerabilities in network devices
Malicious insiders
Threats targeting CSP/ISP subscribers
Overview
Social engineering, phishing and other ways in
Vulnerable kit
The risk of local cells
USIM card vulnerabilities
Conclusion
Authors
Kaspersky
Download PDF
## Introduction
The telecommunications industry keeps the world connected. Telecoms providers build, operate and manage the complex network infrastructures used for voice and data transmission – and they communicate and store vast amounts of sensitive data. This makes them a top target for c
Securelist
Threat intelligence report for the telecommunications industry
blogs_securelist·2016-08-22
Threat intelligence report for the telecommunications industry
Table of Contents
- Introduction
- Executive summary
- Typical threats targeting telecoms
- Conclusion
Authors
- Kaspersky
Download PDF
## Introduction
The telecommunications industry keeps the world connected. Telecoms providers build, operate and manage the complex network infrastructures used for voice and data transmission – and they communicate and store vast amounts of sensitive data. This makes them a top target for cyber-attack.
According to PwC’s Global State of Information Security, 2016, IT security incidents in the telecoms sector increased 45% in 2015 compared to the year before. Telecoms providers need to arm themselves against this growing risk.
In this intelligence report, we cover the main IT security threats facing the telecommunications industry and illustrate t
Recorded Future
October 2025 CVE Landscape
blogs_recorded_future·CVSS 9.8
[CRITICAL] October 2025 CVE Landscape
# October 2025 CVE Landscape: 32 High-Impact Vulnerabilities Demand Immediate Attention
October 2025 saw a significant escalation in vulnerability activity, with Recorded Future's Insikt Group® identifying 32 high-impact vulnerabilities, double the 16 identified in September's CVE report. Twenty-six of these vulnerabilities scored as Very Critical.
What security teams need to know:
- Microsoft dominates: Eight of 32 vulnerabilities affect Microsoft products, including a critical WSUS deserialization flaw (CVE-2025-59287) now being actively exploited
- CL0P ransomware group exploited an Oracle E-Business Suite zero-day (CVE-2025-61882) for data theft and extortion campaigns
- Legacy vulnerabilities persist: Five of the 14 RCE-enabling vulnerabilities are over a decade old, highlighting c
http://arstechnica.com/security/2015/12/unauthorized-code-in-juniper-firewalls-decrypts-encrypted-vpn-traffic/http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10713http://twitter.com/cryptoron/statuses/677900647560253442http://www.forbes.com/sites/thomasbrewster/2015/12/18/juniper-says-it-didnt-work-with-government-to-add-unauthorized-code-to-network-gear/http://www.kb.cert.org/vuls/id/640184http://www.securityfocus.com/bid/79626http://www.securitytracker.com/id/1034489http://www.wired.com/2015/12/juniper-networks-hidden-backdoors-show-the-risk-of-government-backdoors/https://adamcaudill.com/2015/12/17/much-ado-about-juniper/https://forums.juniper.net/t5/Security-Incident-Response/Important-Announcement-about-ScreenOS/ba-p/285554https://github.com/hdm/juniper-cve-2015-7755http://arstechnica.com/security/2015/12/unauthorized-code-in-juniper-firewalls-decrypts-encrypted-vpn-traffic/http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10713http://twitter.com/cryptoron/statuses/677900647560253442http://www.forbes.com/sites/thomasbrewster/2015/12/18/juniper-says-it-didnt-work-with-government-to-add-unauthorized-code-to-network-gear/http://www.kb.cert.org/vuls/id/640184http://www.securityfocus.com/bid/79626http://www.securitytracker.com/id/1034489http://www.wired.com/2015/12/juniper-networks-hidden-backdoors-show-the-risk-of-government-backdoors/https://adamcaudill.com/2015/12/17/much-ado-about-juniper/https://forums.juniper.net/t5/Security-Incident-Response/Important-Announcement-about-ScreenOS/ba-p/285554https://github.com/hdm/juniper-cve-2015-7755https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2015-7755
2015-12-19
Published
2025-10-02
Added to CISA KEV
Exploited in the wild