CRITICAL🇵🇱 Wersja polska

CVE-2026-33771

CVSS 9.1v4.0pub. 2026-04-09upd. 2026-07-13

A Weak Password Requirements vulnerability in the password management function of Juniper Networks CTP OS might allow an unauthenticated, network-based attacker to exploit weak passwords of local accounts and potentially take full control of the device. The password management menu enables the administrator to set password complexity requirements, but these settings are not saved. The issue can be verified with the menu option "Show password requirements". Failure to enforce the intended requirements can lead to weak passwords being used, which significantly increases the likelihood that an attacker can guess these and subsequently attain unauthorized access. This issue affects CTP OS versions 9.2R1 and 9.2R2.

🤖 AI Analysis
How it works

The CTP OS system administrator can set password complexity requirements through a dedicated menu, however, the configured settings are not permanently saved. In practice, this means these requirements are not enforced — users can set arbitrarily simple passwords for local accounts. A remote attacker, without any authentication, can exploit this weakness to conduct brute-force or dictionary attacks on local accounts, significantly increasing the chance of gaining unauthorized access. The status of current password requirements can be verified using the menu option 'Show password requirements'.

Impact

Successful exploitation of the vulnerability may allow an attacker to gain unauthorized access to local device accounts and, as a result, to take full control of the CTP OS device.

Mitigation & patch

Apply patches available from the vendor in accordance with the references (https://kb.juniper.net/JSA107864). Until the fix is implemented, it is recommended to manually enforce a strong password policy for all local accounts and restrict network access to device management interfaces.

Who is affected

Juniper Networks CTP OS in versions 9.2R1 and 9.2R2.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:X/RE:M/U:X
  • Juniper Ctp Operating System

    OS
    Juniper
    9.2
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2023-36845CRITICAL9.8⚠ KEVPL ✓same vendor

RCE przez modyfikację zmiennej PHP w J-Web Juniper Junos OS (EX/SRX)

CVE-2015-7755CRITICAL9.8⚠ KEVPL ✓same vendor

Juniper ScreenOS — backdoor umożliwiający pominięcie uwierzytelnienia (SSH/Telnet)

CVE-2026-33784CRITICAL9.3PL ✓same vendor

Domyślne hasło w Juniper Networks vLWC umożliwia przejęcie urządzenia

CVE-2026-21902CRITICAL9.3PL ✓same vendor

RCE jako root w Juniper Junos OS Evolved — błędne uprawnienia do krytycznego zasobu

CVE-2025-59974CRITICAL9.3PL ✓same vendor

Stored XSS w Juniper Space Security Director — wstrzyknięcie złośliwych skryptów