CVE-2025-13914
Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
09/04/2026
Last modified:
09/04/2026
Description
A Key Exchange without Entity Authentication vulnerability in the SSH implementation of Juniper Networks Apstra allows a unauthenticated, MITM <br />
<br />
attacker to impersonate managed devices.<br />
<br />
Due to insufficient SSH host key validation an attacker can perform a machine-in-the-middle attack on the SSH connections from Apstra to managed devices, enabling an attacker to impersonate a managed device and capture user credentials.<br />
<br />
This issue affects all versions of Apstra before 6.1.1.
Impact
Base Score 4.0
7.00
Severity 4.0
HIGH
Base Score 3.x
8.70
Severity 3.x
HIGH



