VYPR

Juniper Device Manager

by Juniper Networks

CVEs (2)

  • CVE-2018-0044CriOct 10, 2018
    risk 0.64cvss 9.8epss 0.01

    An insecure SSHD configuration in Juniper Device Manager (JDM) and host OS on Juniper NFX Series devices may allow remote unauthenticated access if any of the passwords on the system are empty. The affected SSHD configuration has the PermitEmptyPasswords option set to "yes".…

  • CVE-2020-1669MedOct 16, 2020
    risk 0.41cvss 6.3epss 0.00

    The Juniper Device Manager (JDM) container, used by the disaggregated Junos OS architecture on Juniper Networks NFX350 Series devices, stores password hashes in the world-readable file /etc/passwd. This is not a security best current practice as it can allow an attacker with…