Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-13914

Опубликовано: 09 апр. 2026
Источник: nvd
CVSS3: 8.7
CVSS3: 8.1
EPSS Низкий

Описание

A Key Exchange without Entity Authentication vulnerability in the SSH implementation of Juniper Networks Apstra allows a unauthenticated, MITM

attacker to impersonate managed devices.

Due to insufficient SSH host key validation an attacker can perform a machine-in-the-middle attack on the SSH connections from Apstra to managed devices, enabling an attacker to impersonate a managed device and capture user credentials.

This issue affects all versions of Apstra before 6.1.1.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:juniper:apstra:*:*:*:*:*:*:*:*
Версия до 6.1.1 (исключая)

EPSS

Процентиль: 23%
0.00303
Низкий

8.7 High

CVSS3

8.1 High

CVSS3

Дефекты

CWE-322
NVD-CWE-Other

Связанные уязвимости

CVSS3: 8.7
github
4 месяца назад

A Key Exchange without Entity Authentication vulnerability in the SSH implementation of Juniper Networks Apstra allows a unauthenticated, MITM attacker to impersonate managed devices. Due to insufficient SSH host key validation an attacker can perform a machine-in-the-middle attack on the SSH connections from Apstra to managed devices, enabling an attacker to impersonate a managed device and capture user credentials. This issue affects all versions of Apstra before 6.1.1.

EPSS

Процентиль: 23%
0.00303
Низкий

8.7 High

CVSS3

8.1 High

CVSS3

Дефекты

CWE-322
NVD-CWE-Other