CVSS: v3.1: 8.7 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N) CVSS: v4.0: 7 (CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/R:U/RE:M)
A Key Exchange without Entity Authentication vulnerability in the SSH implementation of Juniper Networks Apstra allows a unauthenticated, MITM attacker to impersonate managed devices.Due to insufficient SSH host key validation an attacker can perform a machine-in-the-middle attack on the SSH connections from Apstra to managed devices, enabling an attacker to impersonate a managed device and capture user credentials.This issue affects all versions of Apstra before 6.1.1.
Juniper SIRT is not aware of any malicious exploitation of this vulnerability.
This issue was discovered during external security research.
The following software releases have been updated to resolve this specific issue: Apstra 6.1.1, and all subsequent releases.
This issue is being tracked as as AOS-56131.
Note: Juniper SIRT's policy is not to evaluate releases which are beyond End of Engineering (EOE) or End of Life (EOL).
There are no known workarounds for this issue.
2026-04-08: Initial Publication
Juniper SIRT would like to acknowledge and thank the German Federal Office for Information Security (BSI) for responsibly reporting this vulnerability.