Product Affected

This issue affects Security Director Policy Enforcer.

Problem

A Missing Authentication for Critical Function in Juniper Networks Security Director Policy Enforcer allows an unauthenticated, network-based attacker to replace legitimate vSRX images with malicious ones.

If a trusted user initiates deployment, Security Director Policy Enforcer will deliver the attacker's uploaded image to VMware NSX instead of a legitimate one.

This issue affects Security Director Policy Enforcer:  

  • All versions before 23.1R1 Hotpatch v3.
This issue does not affect Junos Space Security Director Insights.
 
Juniper SIRT is not aware of any malicious exploitation of this vulnerability.
 
This issue was seen during production usage.

Solution

The following software releases have been updated to resolve this specific issue:
Security Director Policy Enforcer 23.1 Hotpatch v3, 24.1R4, and all subsequent releases.

Additionally, Juniper SIRT suggests action taken to rotate secrets across all devices after upgrading.

This issue is being tracked as 1833604 which is visible on the Customer Support website.

Note: Juniper SIRT's policy is not to evaluate releases which are beyond End of Engineering (EOE) or End of Life (EOL).

Workaround

There are no known workarounds for this issue.
To reduce the risk of exploitation, enable access control lists (ACLs) and other filtering mechanisms to limit access to the device only from trusted users, hosts and networks.

Severity Assessment

Information for how Juniper Networks uses CVSS can be found at KB 16446 [juniper.net] "Common Vulnerability Scoring System (CVSS) and Juniper's Security Advisories."

Modification History

2025-10-08: Initial Publication 

Related Information