CVE-2026-33771 Details
Description
A Weak Password Requirements vulnerability in the password management function of Juniper Networks CTP OS might allow an unauthenticated, network-based attacker to exploit weak passwords of local accounts and potentially take full control of the device. The password management menu enables the administrator to set password complexity requirements, but these settings are not saved. The issue can be verified with the menu option "Show password requirements". Failure to enforce the intended requirements can lead to weak passwords being used, which significantly increases the likelihood that an attacker can guess these and subsequently attain unauthorized access. This issue affects CTP OS versions 9.2R1 and 9.2R2.
A vulnerability exists in Juniper Networks CTP OS versions 9.2R1 and 9.2R2 due to weak password requirements not being properly enforced. This flaw allows an unauthenticated, network-based attacker to exploit local accounts with weak passwords, potentially gaining full control of the device. Although the password management menu allows administrators to set complexity requirements, these settings are not saved. The issue can be verified using the 'Show password requirements' menu option. The failure to enforce password requirements increases the likelihood of unauthorized access.
Users can upgrade to CTP OS version 9.3R1 or any subsequent release to address this vulnerability. Additionally, access lists or firewall filters can be used to limit access to the command-line interface (CLI) from untrusted hosts and administrators.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 13, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://kb.juniper.net/JSA107864 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-521 | Weak Password Requirements | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| juniper ctp operating system | 9.2 r1 9.2 r2 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 13, 2026 | Reanalysis | [email protected] |
| Jul 8, 2026 | Initial Analysis | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 9, 2026 | New CVE Received | [email protected] |