cbcvebase.
CVE-2015-7756
published 2015-12-19

CVE-2015-7756: The encryption implementation in Juniper ScreenOS 6.2.0r15 through 6.2.0r18, 6.3.0r12 before 6.3.0r12b, 6.3.0r13 before 6.3.0r13b, 6.3.0r14 before 6.3.0r14b…

PriorityP275medium5CVSS 2.0
AVNACLAuNCPINAN
ITWVulnCheck KEV
Exploited in the wild
EPSS
2.45%
82.4th percentile
The encryption implementation in Juniper ScreenOS 6.2.0r15 through 6.2.0r18, 6.3.0r12 before 6.3.0r12b, 6.3.0r13 before 6.3.0r13b, 6.3.0r14 before 6.3.0r14b, 6.3.0r15 before 6.3.0r15b, 6.3.0r16 before 6.3.0r16b, 6.3.0r17 before 6.3.0r17b, 6.3.0r18 before 6.3.0r18b, 6.3.0r19 before 6.3.0r19b, and 6.3.0r20 before 6.3.0r21 makes it easier for remote attackers to discover the plaintext content of VPN sessions by sniffing the network for ciphertext data and conducting an unspecified decryption attack.

Affected

5 ranges
VendorProductVersion rangeFixed in
juniperscreenos
juniperscreenos
juniperscreenos
juniperscreenos
juniperscreenos

Detection & IOCsextracted from sources · hover to see the quote

  • Detect passive VPN traffic sniffing attempts against Juniper ScreenOS devices — attackers sniff ciphertext from VPN sessions over the network to conduct offline decryption attacks
  • Flag Juniper ScreenOS devices running versions 6.2.0r15 through 6.2.0r18 or 6.3.0r12 through 6.3.0r20 (pre-patch) as high-priority targets for this VPN decryption vulnerability
  • ·CVE-2015-7756 is a VPN encryption weakness in Juniper ScreenOS; it is distinct from CVE-2015-7755 (the unauthorized admin access backdoor), though both affect ScreenOS and are addressed in the same out-of-cycle security bulletin
  • ·Vendor advisory for both CVE-2015-7755 and CVE-2015-7756 is located at the Juniper support portal out-of-cycle bulletin; patched versions are 6.3.0r12b, r13b, r14b, r15b, r16b, r17b, r18b, r19b, and r21 for the 6.3 branch, and no patch listed within the 6.2 branch (discontinue use)

CVSS provenance

nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vulncheck5.0MEDIUM
cisa9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.