CVE-2015-7756
published 2015-12-19CVE-2015-7756: The encryption implementation in Juniper ScreenOS 6.2.0r15 through 6.2.0r18, 6.3.0r12 before 6.3.0r12b, 6.3.0r13 before 6.3.0r13b, 6.3.0r14 before 6.3.0r14b…
PriorityP275medium5CVSS 2.0
AVNACLAuNCPINAN
ITWVulnCheck KEV
Exploited in the wild
EPSS
2.45%
82.4th percentile
The encryption implementation in Juniper ScreenOS 6.2.0r15 through 6.2.0r18, 6.3.0r12 before 6.3.0r12b, 6.3.0r13 before 6.3.0r13b, 6.3.0r14 before 6.3.0r14b, 6.3.0r15 before 6.3.0r15b, 6.3.0r16 before 6.3.0r16b, 6.3.0r17 before 6.3.0r17b, 6.3.0r18 before 6.3.0r18b, 6.3.0r19 before 6.3.0r19b, and 6.3.0r20 before 6.3.0r21 makes it easier for remote attackers to discover the plaintext content of VPN sessions by sniffing the network for ciphertext data and conducting an unspecified decryption attack.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| juniper | screenos | — | — |
| juniper | screenos | — | — |
| juniper | screenos | — | — |
| juniper | screenos | — | — |
| juniper | screenos | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect passive VPN traffic sniffing attempts against Juniper ScreenOS devices — attackers sniff ciphertext from VPN sessions over the network to conduct offline decryption attacks ↗
- →Flag Juniper ScreenOS devices running versions 6.2.0r15 through 6.2.0r18 or 6.3.0r12 through 6.3.0r20 (pre-patch) as high-priority targets for this VPN decryption vulnerability ↗
- ·CVE-2015-7756 is a VPN encryption weakness in Juniper ScreenOS; it is distinct from CVE-2015-7755 (the unauthorized admin access backdoor), though both affect ScreenOS and are addressed in the same out-of-cycle security bulletin ↗
- ·Vendor advisory for both CVE-2015-7755 and CVE-2015-7756 is located at the Juniper support portal out-of-cycle bulletin; patched versions are 6.3.0r12b, r13b, r14b, r15b, r16b, r17b, r18b, r19b, and r21 for the 6.3 branch, and no patch listed within the 6.2 branch (discontinue use) ↗
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vulncheck5.0MEDIUM
cisa9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-fq6r-qhq8-2958: The encryption implementation in Juniper ScreenOS 6
ghsa_unreviewed·2022-05-17
CVE-2015-7756 [MEDIUM] GHSA-fq6r-qhq8-2958: The encryption implementation in Juniper ScreenOS 6
The encryption implementation in Juniper ScreenOS 6.2.0r15 through 6.2.0r18, 6.3.0r12 before 6.3.0r12b, 6.3.0r13 before 6.3.0r13b, 6.3.0r14 before 6.3.0r14b, 6.3.0r15 before 6.3.0r15b, 6.3.0r16 before 6.3.0r16b, 6.3.0r17 before 6.3.0r17b, 6.3.0r18 before 6.3.0r18b, 6.3.0r19 before 6.3.0r19b, and 6.3.0r20 before 6.3.0r21 makes it easier for remote attackers to discover the plaintext content of VPN sessions by sniffing the network for ciphertext data and conducting an unspecified decryption attack.
VulnCheck
Juniper ScreenOS VPN Sessions Unspecified Decryption Attack Vulnerability
vulncheck·2015·CVSS 5.0
CVE-2015-7756 [MEDIUM] Juniper ScreenOS VPN Sessions Unspecified Decryption Attack Vulnerability
Juniper ScreenOS VPN Sessions Unspecified Decryption Attack Vulnerability
The encryption implementation in Juniper ScreenOS 6.2.0r15 through 6.2.0r18, 6.3.0r12 before 6.3.0r12b, 6.3.0r13 before 6.3.0r13b, 6.3.0r14 before 6.3.0r14b, 6.3.0r15 before 6.3.0r15b, 6.3.0r16 before 6.3.0r16b, 6.3.0r17 before 6.3.0r17b, 6.3.0r18 before 6.3.0r18b, 6.3.0r19 before 6.3.0r19b, and 6.3.0r20 before 6.3.0r21 makes it easier for remote attackers to discover the plaintext content of VPN sessions by sniffing the network for ciphertext data and conducting an unspecified decryption attack.
Affected: Juniper ScreenOS
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://secu
CISA
Juniper ScreenOS Improper Authentication Vulnerability
cisa·2025-10-02·CVSS 9.8
CVE-2015-7755 [CRITICAL] CWE-287 Juniper ScreenOS Improper Authentication Vulnerability
Vulnerability: Juniper ScreenOS Improper Authentication Vulnerability
Affected: Juniper ScreenOS
Juniper ScreenOS contains an improper authentication vulnerability that could allow unauthorized remote administrative access to the device.
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Notes: https://supportportal.juniper.net/s/article/2015-12-Out-of-Cycle-Security-Bulletin-ScreenOS-Multiple-Security-issues-with-ScreenOS-CVE-2015-7755-CVE-2015-7756 ; https://nvd.nist.gov/vuln/detail/CVE-2015-7755
Remediation Due Date: 2025-10-23
Juniper
CVE-2015-7756: The encryption implementation in Juniper ScreenOS 6.2.0r15 through 6.2.0r18, 6.3.0r12 before 6.3.0r12b, 6.3.0r13 before 6.3.0r13b, 6.3.0r14 before 6.3
vendor_juniper·2015-12-19·CVSS 5.0
CVE-2015-7756 [MEDIUM] CWE-310 CVE-2015-7756: The encryption implementation in Juniper ScreenOS 6.2.0r15 through 6.2.0r18, 6.3.0r12 before 6.3.0r12b, 6.3.0r13 before 6.3.0r13b, 6.3.0r14 before 6.3
CVE-2015-7756: The encryption implementation in Juniper ScreenOS 6.2.0r15 through 6.2.0r18, 6.3.0r12 before 6.3.0r12b, 6.3.0r13 before 6.3.0r13b, 6.3.0r14 before 6.3.0r14b, 6.3.0r15 before 6.3.0r15b, 6.3.0r16 before 6.3.0r16b, 6.3.0r17 before 6.3.0r17b, 6.3.0r18 before 6.3.0r18b, 6.3.0r19 before 6.3.0r19b, and 6.3.0r20 before 6.3.0r21 makes it easier for remote attackers to discover the plaintext content of VPN sessions by sniffing the network for ciphertext data and conducting an unspecified decryption attack.
No detection rules found.
No public exploits indexed.
Securelist
Threat intelligence report for the telecommunications industry
blogs_securelist·2016-08-22
Threat intelligence report for the telecommunications industry
Table of Contents
Introduction
Executive summary
Typical threats targeting telecoms
Overview
Threats directed at telecoms companies
DDoS
Targeted attacks
Unaddressed software vulnerabilities
The impact of service misconfiguration
Vulnerabilities in network devices
Malicious insiders
Threats targeting CSP/ISP subscribers
Overview
Social engineering, phishing and other ways in
Vulnerable kit
The risk of local cells
USIM card vulnerabilities
Conclusion
Authors
Kaspersky
Download PDF
## Introduction
The telecommunications industry keeps the world connected. Telecoms providers build, operate and manage the complex network infrastructures used for voice and data transmission – and they communicate and store vast amounts of sensitive data. This makes them a top target for c
Securelist
Threat intelligence report for the telecommunications industry
blogs_securelist·2016-08-22
Threat intelligence report for the telecommunications industry
Table of Contents
- Introduction
- Executive summary
- Typical threats targeting telecoms
- Conclusion
Authors
- Kaspersky
Download PDF
## Introduction
The telecommunications industry keeps the world connected. Telecoms providers build, operate and manage the complex network infrastructures used for voice and data transmission – and they communicate and store vast amounts of sensitive data. This makes them a top target for cyber-attack.
According to PwC’s Global State of Information Security, 2016, IT security incidents in the telecoms sector increased 45% in 2015 compared to the year before. Telecoms providers need to arm themselves against this growing risk.
In this intelligence report, we cover the main IT security threats facing the telecommunications industry and illustrate t
http://arstechnica.com/security/2015/12/unauthorized-code-in-juniper-firewalls-decrypts-encrypted-vpn-traffic/http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10713http://www.forbes.com/sites/thomasbrewster/2015/12/18/juniper-says-it-didnt-work-with-government-to-add-unauthorized-code-to-network-gear/http://www.kb.cert.org/vuls/id/640184http://www.securitytracker.com/id/1034489http://www.wired.com/2015/12/juniper-networks-hidden-backdoors-show-the-risk-of-government-backdoors/https://adamcaudill.com/2015/12/17/much-ado-about-juniper/https://forums.juniper.net/t5/Security-Incident-Response/Important-Announcement-about-ScreenOS/ba-p/285554https://github.com/hdm/juniper-cve-2015-7755http://arstechnica.com/security/2015/12/unauthorized-code-in-juniper-firewalls-decrypts-encrypted-vpn-traffic/http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10713http://www.forbes.com/sites/thomasbrewster/2015/12/18/juniper-says-it-didnt-work-with-government-to-add-unauthorized-code-to-network-gear/http://www.kb.cert.org/vuls/id/640184http://www.securitytracker.com/id/1034489http://www.wired.com/2015/12/juniper-networks-hidden-backdoors-show-the-risk-of-government-backdoors/https://adamcaudill.com/2015/12/17/much-ado-about-juniper/https://forums.juniper.net/t5/Security-Incident-Response/Important-Announcement-about-ScreenOS/ba-p/285554https://github.com/hdm/juniper-cve-2015-7755
2015-12-19
Published
Exploited in the wild