CVE-2025-11198 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

A Missing Authentication for Critical Function vulnerability in Juniper Networks Security Director Policy Enforcer allows an unauthenticated, network-based atta…
High CVSS: 8.5

CVE-2025-11198

A Missing Authentication for Critical Function vulnerability in Juniper Networks Security Director Policy Enforcer allows an unauthenticated, network-based attacker to replace legitimate vSRX images with malicious ones.



If a trusted user initiates deployment, Security Director Policy Enforcer will deliver the attacker's uploaded image to VMware NSX instead of a legitimate one.





This issue affects Security Director Policy Enforcer:  



* All versions before 23.1R1 Hotpatch v3.


This issue does not affect Junos Space Security Director Insights.
Vendor
Juniper
Product
Security Director Policy Enforcer
CWE
CWE-306
Yayın Tarihi
2025-10-09 16:15:44
Güncelleme
2026-01-26 18:29:28
Source Identifier
sirt@juniper.net
KEV Date Added
-

Kategoriler

Referanslar