peter bassill · operator
$ cve CVE-2015-7755 JSON

CVE-2015-7755 KEV

9.8
CRITICAL · CVSS 3.1 · EPSS 61.1% (pctl 99)

Patch first

On CISA KEV — known exploited in the wild, due 2025-10-23.

Description

Juniper ScreenOS 6.2.0r15 through 6.2.0r18, 6.3.0r12 before 6.3.0r12b, 6.3.0r13 before 6.3.0r13b, 6.3.0r14 before 6.3.0r14b, 6.3.0r15 before 6.3.0r15b, 6.3.0r16 before 6.3.0r16b, 6.3.0r17 before 6.3.0r17b, 6.3.0r18 before 6.3.0r18b, 6.3.0r19 before 6.3.0r19b, and 6.3.0r20 before 6.3.0r21 allows remote attackers to obtain administrative access by entering an unspecified password during a (1) SSH or (2) TELNET session.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS61.14% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-287
On CISA KEVyes — remediate by 2025-10-23
Public exploitnone known
Published2015-12-19
Last modified2026-06-17

CISA KEV

NameJuniper ScreenOS Improper Authentication Vulnerability
Added2025-10-02
Due2025-10-23
Vendor / productJuniper / ScreenOS
Ransomware usenone reported

Affected (1)

VendorProduct
juniperscreenos

References

→ the Explorer  ·  watch your stack  ·  NVD