← Back to CVE List
Vulnerability Intelligence Report
NFX Series: Hard-coded credentials allow an attacker to take control of any instance through administrative interfaces.

CVE-2021-0248

This issue is not applicable to NFX NextGen Software. On NFX Series devices the use of Hard-coded Credentials in Juniper Networks Junos OS allows an attacker to take over any instance of an NFX deployment. This issue is only exploitable through administrative interfaces. This issue affects: Juniper Networks Junos OS versions prior to 19.1R1 on NFX Series. No other platforms besides NFX Series devices are affected.

No Active Exploit Signals
CVSS Base Score
10.0
CRITICAL
Exploitability:3.9
Impact Score:6.1
EPSS Probability:1.03%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-798 ↗CWE-798 Use of Hard-coded Credentials

Affected Products & Versions

Vendor Product Affected Versions
Juniper Networks Junos OS unspecified < 19.1R1 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
1.030%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityJuniper Networks, Inc. · Vendor · USA
Reserved2020-10-27T00:00:00
Published2021-04-22T19:37:11
Patch Date2021-04-14
Last Updated2024-09-16T22:09:18

LINK COPIED TO CLIPBOARD