CVE-2015-7755 is a critical authentication bypass vulnerability affecting Juniper ScreenOS versions 6.2.0r15 through 6.2.0r18 and various 6.3.0rX releases before their respective 'b' patch versions. This flaw allows remote attackers to gain administrative access to affected devices via SSH or TELNET by entering an unspecified password. With a CVSS score of 9.8 (CRITICAL), the vulnerability is easily exploitable over the network with low attack complexity, leading to complete compromise of confidentiality, integrity, and availability. This vulnerability is actively exploited in the wild, has a high EPSS score, and is supported by a Metasploit module, indicating widespread exploitability and significant community attention with numerous discussions and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
6.3.0CPE matchmatch criteria | cpe:2.3:o:juniper:screenos:6.3.0:r17:*:*:*:*:*:* | ||
6.3.0CPE matchmatch criteria | cpe:2.3:o:juniper:screenos:6.3.0:r18:*:*:*:*:*:* | ||
6.3.0CPE matchmatch criteria | cpe:2.3:o:juniper:screenos:6.3.0:r19:*:*:*:*:*:* | ||
6.3.0CPE matchmatch criteria | cpe:2.3:o:juniper:screenos:6.3.0:r20:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.