CRITICAL🇵🇱 Wersja polska

CVE-2026-33784

CVSS 9.3v4.0pub. 2026-04-09upd. 2026-07-08

A Use of Default Password vulnerability in the Juniper Networks Support Insights (JSI) Virtual Lightweight Collector (vLWC) allows an unauthenticated, network-based attacker to take full control of the device. vLWC software images ship with an initial password for a high privileged account. A change of this password is not enforced during the provisioning of the software, which can make full access to the system by unauthorized actors possible.This issue affects all versions of vLWC before 3.0.94.

🤖 AI Analysis
How it works

vLWC software images are delivered with a default password assigned to a high-privilege account. During the provisioning process, changing this password is not required, which means that after system deployment, the account can still be accessed with the original, predictable password. An attacker with network access can exploit these credentials to log in and gain full system access without needing any prior permissions.

Impact

An attacker can gain full control over the vLWC device, including the ability to read, modify, and disrupt the operation of the system collecting diagnostic data and network support.

Mitigation & patch

Update vLWC software to version 3.0.94 or later. Until the patch is applied, it is recommended to manually change the default password of the privileged account and restrict network access to the device management interface. Detailed instructions are available in the manufacturer's guide: https://kb.juniper.net/JSA107871

Who is affected

All versions of Juniper Networks Support Insights (JSI) Virtual Lightweight Collector (vLWC) before version 3.0.94

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:X/RE:L/U:X
  • Juniper Virtual Lightweight Collector

    APP
    Juniper
    < 3.0.94
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2026-21915HIGH8.4same product

A Permissive List of Allowed Input vulnerability in the CLI of Juniper Networks Support Insights (JSI) Virtual...

CVE-2023-36845CRITICAL9.8⚠ KEVPL ✓same vendor

RCE przez modyfikację zmiennej PHP w J-Web Juniper Junos OS (EX/SRX)

CVE-2015-7755CRITICAL9.8⚠ KEVPL ✓same vendor

Juniper ScreenOS — backdoor umożliwiający pominięcie uwierzytelnienia (SSH/Telnet)

CVE-2026-33771CRITICAL9.1PL ✓same vendor

Słabe wymagania hasła w Juniper Networks CTP OS — przejęcie urządzenia

CVE-2026-21902CRITICAL9.3PL ✓same vendor

RCE jako root w Juniper Junos OS Evolved — błędne uprawnienia do krytycznego zasobu