CVSS: v3.1: 8.6 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N) CVSS: v4.0: 7.7 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:H/SA:N/AU:Y/R:A/V:C/RE:M/U:Green)
Required Configuration for Exposure: Create a Metadata using the Create Metadata administrative page.
Juniper SIRT is not aware of any malicious exploitation of these vulnerabilities.
This issue was seen during production usage.
This issue is being tracked as 1867545 which is visible on the Customer Support website.
Note: Juniper SIRT's policy is not to evaluate releases which are beyond End of Engineering (EOE) or End of Life (EOL).
There are no known workarounds for this issue.To reduce the risk of exploitation, enable access control lists (ACLs) and other filtering mechanisms to limit access to the device only from trusted users, hosts and networks.
2025-10-08: Initial Publication