Impact
Juniper Networks Apstra contains a Key Exchange without Entity Authentication flaw in its SSH implementation that allows an unauthenticated attacker to perform a man‑in‑the‑middle attack on the SSH connections between Apstra and its managed devices. The flaw manifests as insufficient host‑key validation, enabling the attacker to impersonate a device, intercept credentials, and potentially gain unauthorized access. The weakness is classified as CWE‑322.
Affected Systems
The vulnerability affects every Juniper Apstra release prior to 6.1.1. Any deployment of Apstra versions older than 6.1.1 running the SSH client used to communicate with managed devices is at risk. Versions 6.1.1 and later have been updated to resolve this specific issue.
Risk and Exploitability
The CVSS v3.1 score of 7.0 indicates high severity. The EPSS score of less than 1% suggests that exploitation is currently unlikely, though it has not been ruled out. The vulnerability is not listed in the CISA KEV catalog. An attacker who can intercept traffic between Apstra and its target devices—such as by compromising a network device or gaining access to a shared network segment—could launch the MitM and capture credentials. Because the attack does not require authentication to Apstra, the potential impact remains significant in exposed or poorly segmented environments.
OpenCVE Enrichment