Juniper Security Director: Attackers can bypass security mechanism

Important security updates have been released for Junos OS and Junos Space, among others. Networks can be compromised.

listen Print view
The letters IP against a dark background with network symbols

(Image: FlashMovie / shutterstock.com)

4 min. read

Several products from network equipment manufacturer Juniper are vulnerable. If attacks are successful, attackers can install manipulated images or embed backdoors in switches, for example. Security patches are available for download.

Juniper lists the affected products in the support portal. Network admins can also find information on the patches there. As a list is beyond the scope of this report, the warning messages are linked below this article. So far, there are no indications of ongoing attacks. It is also unclear at this stage how admins can recognize instances that have already been successfully attacked.

The most dangerous is a vulnerability (CVE-2025-59968 "high") in the Juniper Security Director security solution, which is supposed to protect networks. Due to a lack of authorization, attackers can modify metadata via the web interface. This can lead to network data traffic that is actually blocked getting through.

A security vulnerability (CVE-2025-60004 "high") in Junos OS Evolved can lead to DoS states. According to the description, no authentication is required for attackers. Further DoS vulnerabilities (CVE-2025-59964 "high", CVE-2025-59975 "high") affect Junos OS and Junos Space.

Due to authentication errors, attackers can manipulate and upload vSRX images in the context of Security Director Policy Enforcer (CVE-2025-11198 "high"). The remaining vulnerabilities are categorised as "medium" threat level. They primarily impact Junos OS and attackers can use them to install backdoors, among other things.

Videos by heise

Listing sorted by threat level in descending order:

(des)

Don't miss any news – follow us on Facebook, LinkedIn or Mastodon.

This article was originally published in German. It was translated with technical assistance and editorially reviewed before publication.