CVE-2018-0044

CRITICAL

Juniper Junos 18.1r1-18.1r3 - Unauthenticated Remote Access via Empty Password SSHD Configuration

Title source: llm
STIX 2.1

Description

An insecure SSHD configuration in Juniper Device Manager (JDM) and host OS on Juniper NFX Series devices may allow remote unauthenticated access if any of the passwords on the system are empty. The affected SSHD configuration has the PermitEmptyPasswords option set to "yes". Affected releases are Juniper Networks Junos OS: 18.1 versions prior to 18.1R4 on NFX Series.

References (2)

Core 2
Core References
Vendor Advisory x_refsource_confirm
https://kb.juniper.net/JSA10878
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/105565

Scores

CVSS v3 9.8
EPSS 0.0040
EPSS Percentile 60.9%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-287
Status published
Products (1)
juniper/junos 18.1r1 - 18.1r3
Published Oct 10, 2018
Tracked Since Feb 18, 2026