Missing Authentication Vulnerability in Juniper Networks Security Director Policy Enforcer
CVE-2025-11198

8.5HIGH

Key Information:

Vendor
CVE Published:
9 October 2025

Badges

👾 Exploit Exists

What is CVE-2025-11198?

A vulnerability in Juniper Networks Security Director Policy Enforcer allows network-based attackers to exploit missing authentication mechanisms. This flaw enables unauthorized users to upload malicious virtual SRX (vSRX) images. When a legitimate deployment is initiated by a trusted user, the Security Director Policy Enforcer may mistakenly deliver the attacker's crafted image to VMware NSX, compromising the integrity of network configurations. It is crucial for organizations using affected versions to apply necessary patches to mitigate risk.

Affected Version(s)

Security Director Policy Enforcer 0 < 23.1R1 Hotpatch v3

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-11198 : Missing Authentication Vulnerability in Juniper Networks Security Director Policy Enforcer