cbcvebase.
CVE-2015-7755
published 2015-12-19

CVE-2015-7755: Juniper ScreenOS 6.2.0r15 through 6.2.0r18, 6.3.0r12 before 6.3.0r12b, 6.3.0r13 before 6.3.0r13b, 6.3.0r14 before 6.3.0r14b, 6.3.0r15 before 6.3.0r15b…

PriorityP196critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2025-10-23
Exploited in the wild
EPSS
61.40%
99.1th percentile
Juniper ScreenOS 6.2.0r15 through 6.2.0r18, 6.3.0r12 before 6.3.0r12b, 6.3.0r13 before 6.3.0r13b, 6.3.0r14 before 6.3.0r14b, 6.3.0r15 before 6.3.0r15b, 6.3.0r16 before 6.3.0r16b, 6.3.0r17 before 6.3.0r17b, 6.3.0r18 before 6.3.0r18b, 6.3.0r19 before 6.3.0r19b, and 6.3.0r20 before 6.3.0r21 allows remote attackers to obtain administrative access by entering an unspecified password during a (1) SSH or (2) TELNET session.

Affected

1 ranges
VendorProductVersion rangeFixed in
juniperscreenos

Detection & IOCsextracted from sources · hover to see the quote

command<<< %s(un='%s') = %u
port22 (SSH)
port23 (TELNET)
  • Scan for Juniper ScreenOS devices accepting the hardcoded backdoor password '<<< %s(un='%s') = %u' on SSH or Telnet; any username is valid with this password.
  • Alert on successful SSH or Telnet administrative logins to Juniper ScreenOS 6.2.0r15–6.2.0r18 or 6.3.0r12–6.3.0r20 from unexpected sources, as the backdoor grants access with any username and the magic password.
  • ·The backdoor is valid on both SSH and Telnet sessions; any username combined with the magic password string grants administrative access — authentication bypass is not protocol-specific.
  • ·Affected versions span ScreenOS 6.2.0r15–6.2.0r18 and 6.3.0r12–6.3.0r20; patched versions include 6.3.0r12b, 6.3.0r13b through 6.3.0r19b, and 6.3.0r21.
  • ·CISA KEV classifies this as an improper authentication vulnerability enabling unauthorized remote administrative access; vendor mitigations must be applied or the product discontinued.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vulncheck9.8CRITICAL
cisa9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.