A Weak Password Requirements vulnerability in the password management function of Juniper Networks CTP OS might allow an unauthenticated, network-based attacker to exploit weak passwords of local accounts and potentially take full control of the device. The password management menu enables the administrator to set password complexity requirements, but these settings are not saved. The issue can be verified with the menu option "Show password requirements". Failure to enforce the intended requirements can lead to weak passwords being used, which significantly increases the likelihood that an attacker can guess these and subsequently attain unauthorized access. This issue affects CTP OS versions 9.2R1 and 9.2R2.
The CTP OS system administrator can set password complexity requirements through a dedicated menu, however, the configured settings are not permanently saved. In practice, this means these requirements are not enforced — users can set arbitrarily simple passwords for local accounts. A remote attacker, without any authentication, can exploit this weakness to conduct brute-force or dictionary attacks on local accounts, significantly increasing the chance of gaining unauthorized access. The status of current password requirements can be verified using the menu option 'Show password requirements'.
Successful exploitation of the vulnerability may allow an attacker to gain unauthorized access to local device accounts and, as a result, to take full control of the CTP OS device.
Apply patches available from the vendor in accordance with the references (https://kb.juniper.net/JSA107864). Until the fix is implemented, it is recommended to manually enforce a strong password policy for all local accounts and restrict network access to device management interfaces.
Juniper Networks CTP OS in versions 9.2R1 and 9.2R2.
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:X/RE:M/U:XJuniper Ctp Operating System
OSJuniper9.2
Related vulnerabilities
RCE przez modyfikację zmiennej PHP w J-Web Juniper Junos OS (EX/SRX)
Juniper ScreenOS — backdoor umożliwiający pominięcie uwierzytelnienia (SSH/Telnet)
Domyślne hasło w Juniper Networks vLWC umożliwia przejęcie urządzenia
RCE jako root w Juniper Junos OS Evolved — błędne uprawnienia do krytycznego zasobu
Stored XSS w Juniper Space Security Director — wstrzyknięcie złośliwych skryptów