CVE-2015-7756 describes a flaw in the encryption implementation of Juniper ScreenOS versions 6.2.0r15 through 6.2.0r18 and various 6.3.0r versions. This vulnerability allows remote attackers to more easily decrypt VPN session content by sniffing network traffic and performing an unspecified decryption attack. With a CVSS score of 5.0, it presents a moderate risk, requiring no authentication and low attack complexity, primarily impacting confidentiality. While there is no KEV entry or known public exploit code, the vulnerability has garnered significant community discussion and media coverage, indicating high awareness and potential for exploitation despite its inactive Hot List status.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
6.2.0r15CPE matchmatch criteria | cpe:2.3:o:juniper:screenos:6.2.0r15:*:*:*:*:*:*:* | ||
6.2.0r16CPE matchmatch criteria | cpe:2.3:o:juniper:screenos:6.2.0r16:*:*:*:*:*:*:* | ||
6.2.0r17CPE matchmatch criteria | cpe:2.3:o:juniper:screenos:6.2.0r17:*:*:*:*:*:*:* | ||
6.2.0r18CPE matchmatch criteria | cpe:2.3:o:juniper:screenos:6.2.0r18:*:*:*:*:*:*:* | ||
6.3.0CPE matchmatch criteria | cpe:2.3:o:juniper:screenos:6.3.0:r12:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.