← CVE Tracker
7.4HIGH

CVE-2025-11198 — A Missing Authentication for Critical Function vulnerability in Juniper Networks Security Director Policy…

Juniper · Security Director Policy Enforcer · Published 9 Oct 2025 · Modified 30 Sept 2026

Description

A Missing Authentication for Critical Function vulnerability in Juniper Networks Security Director Policy Enforcer allows an unauthenticated, network-based attacker to replace legitimate vSRX images with malicious ones. If a trusted user initiates deployment, Security Director Policy Enforcer will deliver the attacker's uploaded image to VMware NSX instead of a legitimate one. This issue affects Security Director Policy Enforcer:   * All versions before 23.1R1 Hotpatch v3. This issue does not affect Junos Space Security Director Insights.

References

What to do
  1. Check whether Security Director Policy Enforcer is in your asset inventory.
  2. Patch in the next maintenance window; prioritise internet-facing systems.
  3. Record the decision in your risk register for audit evidence.
Alert me on similar CVEs →
Share

Link: adminadda.com/cve/CVE-2025-11198