CVE-2018-0044
NFX Series: Insecure sshd configuration in Juniper Device Manager (JDM) and host OS
Vexday Risk Score
28Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 9.8EPSS 1.3%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
10 Oct 2018Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
An insecure SSHD configuration in Juniper Device Manager (JDM) and host OS on Juniper NFX Series devices may allow remote unauthenticated access if any of the passwords on the system are empty. The affected SSHD configuration has the PermitEmptyPasswords option set to "yes". Affected releases are Juniper Networks Junos OS: 18.1 versions prior to 18.1R4 on NFX Series.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
Juniper Networks · Junos OSWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →