CVE-2020-1614
published 2020-04-08CVE-2020-1614: A Use of Hard-coded Credentials vulnerability exists in the NFX250 Series for the vSRX Virtual Network Function (VNF) instance, which allows an attacker to…
PriorityP264critical10CVSS 3.1
AVNACLPRNUINSCCHIHAH
EPSS
1.36%
68.8th percentile
A Use of Hard-coded Credentials vulnerability exists in the NFX250 Series for the vSRX Virtual Network Function (VNF) instance, which allows an attacker to take control of the vSRX VNF instance if they have the ability to access an administrative service (e.g. SSH) on the VNF, either locally, or through the network. This issue only affects the NFX250 Series vSRX VNF. No other products or platforms are affected. This issue is only applicable to environments where the vSRX VNF root password has not been configured. This issue affects the Juniper Networks NFX250 Network Services Platform vSRX VNF instance on versions prior to 19.2R1.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| juniper | junos | < 19.2 | 19.2 |
| juniper | junos | — | — |
| juniper | srx_series | — | — |
| juniper_networks | juniper_networks_nfx_series_network_services_platform | >= unspecified < 19.2R1 | 19.2R1 |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect exploitation attempts by monitoring for SSH authentication to the vSRX VNF instance using hard-coded/default root credentials, particularly when the root password has not been configured. ↗
- →Alert on successful root-level SSH logins to NFX250 vSRX VNF instances, especially in environments where the vSRX VNF root password has not been explicitly configured. ↗
- ·Vulnerability only affects NFX250 Series vSRX VNF instances running versions prior to 19.2R1. No other Juniper products or platforms are affected. ↗
- ·The hard-coded credentials vulnerability is only exploitable when the vSRX VNF root password has not been set by the administrator — environments with a configured root password are not affected. ↗
- ·Attack surface includes both local and remote network access to administrative services such as SSH on the VNF. ↗
CVSS provenance
nvdv3.110.0CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Juniper
CVE-2020-1614: A Use of Hard-coded Credentials vulnerability exists in the NFX250 Series for the vSRX Virtual Network Function (VNF) instance, which allows an attack
vendor_juniper·2020-04-08·CVSS 10.0
CVE-2020-1614 [CRITICAL] CWE-798 CVE-2020-1614: A Use of Hard-coded Credentials vulnerability exists in the NFX250 Series for the vSRX Virtual Network Function (VNF) instance, which allows an attack
CVE-2020-1614: A Use of Hard-coded Credentials vulnerability exists in the NFX250 Series for the vSRX Virtual Network Function (VNF) instance, which allows an attacker to take control of the vSRX VNF instance if they have the ability to access an administrative service (e.g. SSH) on the VNF, either locally, or through the network. This issue only affects the NFX250 Series vSRX VNF. No other products or platforms are affected. This issue is only applicable to environments where the vSRX VNF root password has not been configured. This issue affects the Juniper Networks NFX250 Network Services Platform vSRX VNF instance on versions prior to 19.2R1.
GHSA
GHSA-mrrq-pc5g-fmm4: A Use of Hard-coded Credentials vulnerability exists in the NFX250 Series for the vSRX Virtual Network Function (VNF) instance, which allows an attack
ghsa_unreviewed·2022-05-24
CVE-2020-1614 [HIGH] GHSA-mrrq-pc5g-fmm4: A Use of Hard-coded Credentials vulnerability exists in the NFX250 Series for the vSRX Virtual Network Function (VNF) instance, which allows an attack
A Use of Hard-coded Credentials vulnerability exists in the NFX250 Series for the vSRX Virtual Network Function (VNF) instance, which allows an attacker to take control of the vSRX VNF instance if they have the ability to access an administrative service (e.g. SSH) on the VNF, either locally, or through the network. This issue only affects the NFX250 Series vSRX VNF. No other products or platforms are affected. This issue is only applicable to environments where the vSRX VNF root password has not been configured. This issue affects the Juniper Networks NFX250 Network Services Platform vSRX VNF instance on versions prior to 19.2R1.
No detection rules found.
No public exploits indexed.
https://kb.juniper.net/JSA10997https://www.juniper.net/documentation/en_US/release-independent/junos/topics/task/configuration/nfx250-configure-vsrx-internal-ip.htmlhttps://kb.juniper.net/JSA10997https://www.juniper.net/documentation/en_US/release-independent/junos/topics/task/configuration/nfx250-configure-vsrx-internal-ip.html
2020-04-08
Published