cbcvebase.
CVE-2021-0248
published 2021-04-22

CVE-2021-0248: This issue is not applicable to NFX NextGen Software. On NFX Series devices the use of Hard-coded Credentials in Juniper Networks Junos OS allows an attacker…

PriorityP262critical10CVSS 3.1
AVNACLPRNUINSCCHIHAH
EPSS
1.03%
59.9th percentile
This issue is not applicable to NFX NextGen Software. On NFX Series devices the use of Hard-coded Credentials in Juniper Networks Junos OS allows an attacker to take over any instance of an NFX deployment. This issue is only exploitable through administrative interfaces. This issue affects: Juniper Networks Junos OS versions prior to 19.1R1 on NFX Series. No other platforms besides NFX Series devices are affected.

Affected

4 ranges
VendorProductVersion rangeFixed in
juniperjunos< 19.119.1
juniperjunos
juniperjunos_os
juniper_networksjunos_os>= unspecified < 19.1R119.1R1

Detection & IOCsextracted from sources · hover to see the quote

  • Exploitation is limited to administrative interfaces on NFX Series devices running Junos OS prior to 19.1R1; monitor for unexpected or anomalous authentication attempts against administrative interfaces (e.g., SSH, web UI, console) on NFX Series hardware.
  • Scope detection efforts exclusively to NFX Series devices; no other Juniper platforms are affected.
  • ·This vulnerability does NOT affect NFX NextGen Software; only legacy NFX Series devices running Junos OS versions prior to 19.1R1 are vulnerable.
  • ·The hard-coded credentials allow full device takeover; any NFX deployment running affected Junos OS versions should be treated as potentially compromised if administrative interfaces were exposed.

CVSS provenance

nvdv3.110.0CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.