ZeroHour

CVE-2015-7755

KEVlarge

Authentication Bypass in Juniper ScreenOS Grants Remote Admin Access

CISA: Juniper ScreenOS Improper Authentication Vulnerability

CVSS
EPSS
61%p99
Published
KEV added
AI analysis

CVE-2015-7755 is an improper authentication flaw (CWE-287) in Juniper ScreenOS that allows an unauthenticated remote attacker to gain administrative access to affected Juniper firewalls. It is triggered remotely via the device's administrative access path — widely reported as a hardcoded-credential backdoor reachable over SSH/Telnet management sessions, so any network that can reach the management interface is exposed. A successful attacker gains full administrator control of the firewall, enabling configuration changes, traffic manipulation, credential theft, and persistence. Only organizations running Juniper ScreenOS (legacy NetScreen/SSG firewall deployments) are affected. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2025-10-02, confirming exploitation in the wild; no public proof-of-concept is known.

What to do: Per the CISA required action and BOD 22-01, upgrade ScreenOS to a fixed release per Juniper's advisory, or if fixed versions are unavailable for your hardware, discontinue use or immediately restrict SSH and Telnet administrative access to trusted management networks. Audit device logs for unexpected administrative logins, rotate or reset administrative credentials, and treat any long-lived ScreenOS firewall as potentially compromised given the backdoor history and current KEV listing.

Affected
Juniper ScreenOS
Estimated exposure
largeOrder of 10,000+ internet-exposed ScreenOS administrative interfaces (tens of thousands of legacy firewalls) — ScreenOS runs only on legacy Juniper NetScreen/SSG firewalls; internet-wide scans around the 2015 disclosure found tens of thousands of devices with remotely reachable management access, and the shrinking post-end-of-support installed base…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Juniper ScreenOS contains an improper authentication vulnerability that could allow unauthorized remote administrative access to the device.

CISA Known Exploited Vulnerability
Affected
Juniper ScreenOS
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
Juniper
Products
ScreenOS
Weakness
CWE-287

In the news