CVE detail

CVE-2025-11198 — CVE-2025-11198

Published 2025-10-09 · Modified 2026-06-17 · Vendor juniper · Product security_director_policy_enforcer · Source nvd
HIGH
severity
CVSS-derived band
7.4
CVSS v3
0–10 scale
0.0026
EPSS probability
exploitation probability, 30d
17.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog

Description

A Missing Authentication for Critical Function vulnerability in Juniper Networks Security Director Policy Enforcer allows an unauthenticated, network-based attacker to replace legitimate vSRX images with malicious ones. If a trusted user initiates deployment, Security Director Policy Enforcer will deliver the attacker's uploaded image to VMware NSX instead of a legitimate one. This issue affects Security Director Policy Enforcer:   * All versions before 23.1R1 Hotpatch v3. This issue does not affect Junos Space Security Director Insights.

Remediation

vendor remediation guidance

The following software releases have been updated to resolve this specific issue: Security Director Policy Enforcer 23.1 Hotpatch v3, 24.1R4, and all subsequent releases. Additionally, Juniper SIRT suggests action taken to rotate secrets across all devices after upgrading.

workarounds

There are no known workarounds for this issue. To reduce the risk of exploitation, enable access control lists (ACLs) and other filtering mechanisms to limit access to the device only from trusted users, hosts and networks.

ProductVulnerable rangeFixed versionAdvisory
Juniper Networks Security Director Policy Enforcer<23.1R1 Hotpatch v323.1R1 Hotpatch v3advisory ↗

References

cvedb.io · NVD · CISA KEV · FIRST EPSS · vendor advisories (CVE Program List v5). Informational only, no warranty — verify every remediation against the vendor advisory before acting on it. This product uses data from the NVD API but is not endorsed or certified by the NVD, CISA, FIRST.org or any vendor named. CVE® is a registered trademark of The MITRE Corporation.