Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2015-7755 Details

Description

Juniper ScreenOS 6.2.0r15 through 6.2.0r18, 6.3.0r12 before 6.3.0r12b, 6.3.0r13 before 6.3.0r13b, 6.3.0r14 before 6.3.0r14b, 6.3.0r15 before 6.3.0r15b, 6.3.0r16 before 6.3.0r16b, 6.3.0r17 before 6.3.0r17b, 6.3.0r18 before 6.3.0r18b, 6.3.0r19 before 6.3.0r19b, and 6.3.0r20 before 6.3.0r21 allows remote attackers to obtain administrative access by entering an unspecified password during a (1) SSH or (2) TELNET session.

Metrics

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

URLSource(s)Tag(s)
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2015-7755 CISA-ADPUS Government Resource
http://arstechnica.com/security/2015/12/unauthorized-code-in-juniper-firewalls-decrypts-encrypted-vpn-traffic/ CVEThird Party Advisory
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10713 CVEExploitVendor Advisory
https://adamcaudill.com/2015/12/17/much-ado-about-juniper/ CVEThird Party Advisory
https://forums.juniper.net/t5/Security-Incident-Response/Important-Announcement-about-ScreenOS/ba-p/285554 CVEVendor Advisory

see all 23 references

This CVE is in CISA's Known Exploited Vulnerabilities Catalog

Reference CISA's BOD 22-01 and Known Exploited Vulnerabilities Catalog for further guidance and requirements.

Vulnerability NameDate AddedDue DateRequired Action
Juniper ScreenOS Improper Authentication VulnerabilityOct 2, 2025Oct 23, 2025Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness Enumeration

CWE-IDCWE NameSource
CWE-287Improper Authentication[email protected]
CWE-287Improper AuthenticationCISA-ADP

Affected Products

ProductVersions
juniper screenos
6.3.0 r17
6.3.0 r18
6.3.0 r19
6.3.0 r20

CPE

  • cpe:2.3:o:juniper:screenos:6.3.0:r17:*:*:*:*:*:*
  • cpe:2.3:o:juniper:screenos:6.3.0:r18:*:*:*:*:*:*
  • cpe:2.3:o:juniper:screenos:6.3.0:r19:*:*:*:*:*:*
  • cpe:2.3:o:juniper:screenos:6.3.0:r20:*:*:*:*:*:*

Remediation

  • No remediation found in references.

Change History

14 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2015-7755
NVD Published Date:
Dec 19, 2015
NVD Last Modified:
Jun 17, 2026
Source:
[email protected]
CVE-2015-7755 Details - Not Deferred