Missing Authentication Vulnerability in Juniper Networks Security Director Policy Enforcer
CVE-2025-11198
8.5HIGH
What is CVE-2025-11198?
A vulnerability in Juniper Networks Security Director Policy Enforcer allows network-based attackers to exploit missing authentication mechanisms. This flaw enables unauthorized users to upload malicious virtual SRX (vSRX) images. When a legitimate deployment is initiated by a trusted user, the Security Director Policy Enforcer may mistakenly deliver the attacker's crafted image to VMware NSX, compromising the integrity of network configurations. It is crucial for organizations using affected versions to apply necessary patches to mitigate risk.
Affected Version(s)
Security Director Policy Enforcer 0 < 23.1R1 Hotpatch v3