CVE-2015-7754 is a critical vulnerability affecting Juniper ScreenOS versions prior to 6.3.0r21 when ssh-pka is configured and enabled. This flaw allows remote attackers to cause a denial of service or execute arbitrary code through crafted SSH negotiation. With a CVSS score of 8.1 (HIGH), it presents a significant risk due to its network-based attack vector, high impact on confidentiality, integrity, and availability, and low attack complexity. While there is no evidence of active exploitation, nor publicly available exploit code, the vulnerability has garnered some community discussion, including a Reddit post highlighting its severity.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 6.3.0CPE matchmatch criteria | cpe:2.3:o:juniper:screenos:*:r20:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.