← Vulnerability feed

Vulnerability record · CVE-2015-7755 · published 19 December 2015

CVE-2015-7755: Juniper ScreenOS improper authentication grants admin access

Juniper · Screenos

Juniper ScreenOS contains an improper authentication flaw (CWE-287) where entering an unspecified password during an SSH or TELNET session grants administrative access. The issue affects a defined set of 6.2.0 and 6.3.0 releases and matters because it bypasses authentication entirely on perimeter security devices.

9.8 CVSS 3.1 Critical CISA KEV since 2 Oct 2025 EPSS 61% · top 0.9% CWE-287 · Improper authentication
9.8CVSS 3.1 base score, v2 10.0
61%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
23References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Juniper ScreenOS 6.2.0r15 through 6.2.0r18, 6.3.0r12 before 6.3.0r12b, 6.3.0r13 before 6.3.0r13b, 6.3.0r14 before 6.3.0r14b, 6.3.0r15 before 6.3.0r15b, 6.3.0r16 before 6.3.0r16b, 6.3.0r17 before 6.3.0r17b, 6.3.0r18 before 6.3.0r18b, 6.3.0r19 before 6.3.0r19b, and 6.3.0r20 before 6.3.0r21 allows remote attackers to obtain administrative access by entering an unspecified password during a (1) SSH or (2) TELNET session.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityCVSS 9.8 with no authentication required, active KEV listing and very high EPSS make this an urgent perimeter-device risk.

What it is

Juniper ScreenOS contains an improper authentication flaw (CWE-287) where entering an unspecified password during an SSH or TELNET session grants administrative access. The issue affects a defined set of 6.2.0 and 6.3.0 releases and matters because it bypasses authentication entirely on perimeter security devices.

Impact

An unauthenticated remote attacker gains full administrative control of the affected firewall, enabling configuration changes, traffic interception and further compromise of protected networks.

Attack surface

Reachable over the network via SSH or TELNET to the management interface; no authentication or user interaction is required per the CVSS vector (AV:N/AC:L/PR:N/UI:N).

Exploitation

Listed in CISA KEV (added 2025-10-02) and a vendor advisory reference is tagged Exploit, indicating known exploitation; EPSS 30-day probability is 0.614 (99.1st percentile). No ransomware campaign use is documented.

What to do

  • Upgrade ScreenOS to a fixed release (6.3.0r12b, 6.3.0r13b, 6.3.0r14b, 6.3.0r15b, 6.3.0r16b, 6.3.0r17b, 6.3.0r18b, 6.3.0r19b, 6.3.0r21 or later) per Juniper JSA10713.
  • If patching is not possible, discontinue use of the affected product as directed by CISA KEV required action.
  • Restrict SSH and TELNET management access to trusted management networks only; disable TELNET where feasible.
  • Rotate administrative credentials and review device configuration for unauthorized changes.
  • Monitor for and remove any unauthorized code or backdoor artifacts referenced in vendor and third-party advisories.

Detection

  • Audit ScreenOS device logs for successful SSH or TELNET logins that do not correspond to legitimate administrator accounts or expected source IPs.
  • Compare running configuration and system image hashes against known-good baselines to detect unauthorized modification.
  • Alert on management-plane connections from unexpected external or non-management networks.
  • Review authentication logs for logins lacking a normal credential exchange or occurring outside change windows.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2015-7755 to the Known Exploited Vulnerabilities catalog on 2 October 2025 as "Juniper ScreenOS Improper Authentication Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 23 October 2025.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://arstechnica.com/security/2015/12/unauthorized-code-in-juniper-firewalls-decrypts-encrypted-vpn-traffic/ Third Party Advisory
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10713 ExploitVendor Advisory
http://twitter.com/cryptoron/statuses/677900647560253442 Broken Link
http://www.forbes.com/sites/thomasbrewster/2015/12/18/juniper-says-it-didnt-work-with-government-to-add-unauthorized-cod Permissions Required
http://www.kb.cert.org/vuls/id/640184 Third Party Advisory
http://www.securityfocus.com/bid/79626 Broken Link
http://www.securitytracker.com/id/1034489 Broken Link
http://www.wired.com/2015/12/juniper-networks-hidden-backdoors-show-the-risk-of-government-backdoors/ Third Party Advisory
https://adamcaudill.com/2015/12/17/much-ado-about-juniper/ Third Party Advisory
https://forums.juniper.net/t5/Security-Incident-Response/Important-Announcement-about-ScreenOS/ba-p/285554 Vendor Advisory
https://github.com/hdm/juniper-cve-2015-7755 Third Party Advisory
http://arstechnica.com/security/2015/12/unauthorized-code-in-juniper-firewalls-decrypts-encrypted-vpn-traffic/ Third Party Advisory
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10713 ExploitVendor Advisory
http://twitter.com/cryptoron/statuses/677900647560253442 Broken Link
http://www.forbes.com/sites/thomasbrewster/2015/12/18/juniper-says-it-didnt-work-with-government-to-add-unauthorized-cod Permissions Required
http://www.kb.cert.org/vuls/id/640184 Third Party Advisory
http://www.securityfocus.com/bid/79626 Broken Link
http://www.securitytracker.com/id/1034489 Broken Link
http://www.wired.com/2015/12/juniper-networks-hidden-backdoors-show-the-risk-of-government-backdoors/ Third Party Advisory
https://adamcaudill.com/2015/12/17/much-ado-about-juniper/ Third Party Advisory
https://forums.juniper.net/t5/Security-Incident-Response/Important-Announcement-about-ScreenOS/ba-p/285554 Vendor Advisory
https://github.com/hdm/juniper-cve-2015-7755 Third Party Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2015-7755 US Government Resource

Track CVE-2015-7755 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.1CVE-2015-7754Juniper screenos improper input validation vulnerabilityJuniper ScreenOS before 6.3.0r21, when ssh-pka is configured and enabled, allows remote attackers to cause a denial of service (system crash) or exec…EPSS 3.9%7.8CVE-2014-3813Juniper screenos vulnerabilityUnspecified vulnerability in the Juniper Networks NetScreen Firewall products with ScreenOS before 6.3r17, when configured to use the internal DNS lo…EPSS 1.3%7.8CVE-2014-3814Juniper screenos improper input validation vulnerabilityThe Juniper Networks NetScreen Firewall devices with ScreenOS before 6.3r17, when configured to use the internal DNS lookup client, allows remote att…EPSS 1.3%7.8CVE-2014-2842Juniper screenos vulnerabilityJuniper ScreenOS 6.3 and earlier allows remote attackers to cause a denial of service (crash and restart or failover) via a malformed SSL/TLS packet.EPSS 3.5%7.5CVE-2016-1268Juniper screenos improper input validation vulnerabilityThe administrative web services interface in Juniper ScreenOS before 6.3.0r21 allows remote attackers to cause a denial of service (reboot) via a cra…EPSS 1.9%7.1CVE-2013-6958Juniper screenos vulnerabilityJuniper NetScreen Firewall running ScreenOS 5.4, 6.2, or 6.3, when the Ping of Death screen is disabled, allows remote attackers to cause a denial of…EPSS 1.9%6.5CVE-2018-0014Juniper screenos information exposure vulnerabilityJuniper Networks ScreenOS devices do not pad Ethernet packets with zeros, and thus some packets can contain fragments of system memory or data from p…EPSS 0.60%5.4CVE-2017-2337Juniper screenos cross-site scripting vulnerabilityA persistent cross site scripting vulnerability in NetScreen WebUI of Juniper Networks Juniper NetScreen Firewall+VPN running ScreenOS allows a user …EPSS 1.1%

Source: NIST National Vulnerability Database (record CVE-2015-7755), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.