CVE-2025-13914

Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
09/04/2026
Last modified:
09/04/2026

Description

A Key Exchange without Entity Authentication vulnerability in the SSH implementation of Juniper Networks Apstra allows a unauthenticated, MITM <br /> <br /> attacker to impersonate managed devices.<br /> <br /> Due to insufficient SSH host key validation an attacker can perform a machine-in-the-middle attack on the SSH connections from Apstra to managed devices, enabling an attacker to impersonate a managed device and capture user credentials.<br /> <br /> This issue affects all versions of Apstra before 6.1.1.

References to Advisories, Solutions, and Tools