Vulnerability record · CVE-2015-7755 · published 19 December 2015
CVE-2015-7755: Juniper ScreenOS improper authentication grants admin access
Juniper · Screenos
Juniper ScreenOS contains an improper authentication flaw (CWE-287) where entering an unspecified password during an SSH or TELNET session grants administrative access. The issue affects a defined set of 6.2.0 and 6.3.0 releases and matters because it bypasses authentication entirely on perimeter security devices.
Description
Juniper ScreenOS 6.2.0r15 through 6.2.0r18, 6.3.0r12 before 6.3.0r12b, 6.3.0r13 before 6.3.0r13b, 6.3.0r14 before 6.3.0r14b, 6.3.0r15 before 6.3.0r15b, 6.3.0r16 before 6.3.0r16b, 6.3.0r17 before 6.3.0r17b, 6.3.0r18 before 6.3.0r18b, 6.3.0r19 before 6.3.0r19b, and 6.3.0r20 before 6.3.0r21 allows remote attackers to obtain administrative access by entering an unspecified password during a (1) SSH or (2) TELNET session.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication required, active KEV listing and very high EPSS make this an urgent perimeter-device risk.
What it is
Juniper ScreenOS contains an improper authentication flaw (CWE-287) where entering an unspecified password during an SSH or TELNET session grants administrative access. The issue affects a defined set of 6.2.0 and 6.3.0 releases and matters because it bypasses authentication entirely on perimeter security devices.
Impact
An unauthenticated remote attacker gains full administrative control of the affected firewall, enabling configuration changes, traffic interception and further compromise of protected networks.
Attack surface
Reachable over the network via SSH or TELNET to the management interface; no authentication or user interaction is required per the CVSS vector (AV:N/AC:L/PR:N/UI:N).
Exploitation
Listed in CISA KEV (added 2025-10-02) and a vendor advisory reference is tagged Exploit, indicating known exploitation; EPSS 30-day probability is 0.614 (99.1st percentile). No ransomware campaign use is documented.
What to do
- Upgrade ScreenOS to a fixed release (6.3.0r12b, 6.3.0r13b, 6.3.0r14b, 6.3.0r15b, 6.3.0r16b, 6.3.0r17b, 6.3.0r18b, 6.3.0r19b, 6.3.0r21 or later) per Juniper JSA10713.
- If patching is not possible, discontinue use of the affected product as directed by CISA KEV required action.
- Restrict SSH and TELNET management access to trusted management networks only; disable TELNET where feasible.
- Rotate administrative credentials and review device configuration for unauthorized changes.
- Monitor for and remove any unauthorized code or backdoor artifacts referenced in vendor and third-party advisories.
Detection
- Audit ScreenOS device logs for successful SSH or TELNET logins that do not correspond to legitimate administrator accounts or expected source IPs.
- Compare running configuration and system image hashes against known-good baselines to detect unauthorized modification.
- Alert on management-plane connections from unexpected external or non-management networks.
- Review authentication logs for logins lacking a normal credential exchange or occurring outside change windows.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2015-7755 to the Known Exploited Vulnerabilities catalog on 2 October 2025 as "Juniper ScreenOS Improper Authentication Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 23 October 2025.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2015-7755 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2015-7755), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.