The use of multiple hard-coded cryptographic keys in cSRX Series software in Juniper Networks Junos OS allows an attacker to take control of any instance of a cSRX deployment through device management services. This issue affects: Juniper Networks Junos OS on cSRX Series: All versions prior to 20.2R3; 20.3 versions prior to 20.3R2; 20.4 versions prior to 20.4R2.

Published at
2021-04-22
269 days ago
Modified
2021-04-22
269 days ago
2021
Year
The year of the turtle

https://kb.juniper.net/JSA11157

MISC:https://kb.juniper.net/JSA11157

Vulnerability RAW

{
	"Title": {
		"_text": "CVE-2021-0266"
	},
	"Notes": {
		"Note": [
			{
				"_text": "The use of multiple hard-coded cryptographic keys in cSRX Series software in Juniper Networks Junos OS allows an attacker to take control of any instance of a cSRX deployment through device management services. This issue affects: Juniper Networks Junos OS on cSRX Series: All versions prior to 20.2R3; 20.3 versions prior to 20.3R2; 20.4 versions prior to 20.4R2."
			},
			{
				"_text": "2021-04-22"
			},
			{
				"_text": "2021-04-22"
			}
		]
	},
	"CVE": {
		"_text": "CVE-2021-0266"
	},
	"References": {
		"Reference": {
			"URL": {
				"_text": "https://kb.juniper.net/JSA11157"
			},
			"Description": {
				"_text": "MISC:https://kb.juniper.net/JSA11157"
			}
		}
	}
}