CVE-2025-13914

A Key Exchange without Entity Authentication vulnerability in the SSH implementation of Juniper Networks Apstra allows a unauthenticated, MITM attacker to impersonate managed devices. Due to insufficient SSH host key validation an attacker can perform a machine-in-the-middle attack on the SSH connections from Apstra to managed devices, enabling an attacker to impersonate a managed device and capture user credentials. This issue affects all versions of Apstra before 6.1.1.
References
Link Resource
https://kb.juniper.net/JSA107862 Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:juniper:apstra:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-04-09 22:16

Updated : 2026-07-08 03:18


NVD link : CVE-2025-13914

Mitre link : CVE-2025-13914

CVE.ORG link : CVE-2025-13914


JSON object : View

Products Affected

juniper

  • apstra
CWE
CWE-322

Key Exchange without Entity Authentication

NVD-CWE-Other