CVE-2025-13914

A Key Exchange without Entity Authentication vulnerability in the SSH implementation of Juniper Networks Apstra allows a unauthenticated, MITM attacker to impersonate managed devices. Due to insufficient SSH host key validation an attacker can perform a machine-in-the-middle attack on the SSH connections from Apstra to managed devices, enabling an attacker to impersonate a managed device and capture user credentials. This issue affects all versions of Apstra before 6.1.1.
References
Link Resource
https://kb.juniper.net/JSA107862 Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:juniper:apstra:*:*:*:*:*:*:*:*

History

08 Jul 2026, 03:18

Type Values Removed Values Added
References () https://kb.juniper.net/JSA107862 - () https://kb.juniper.net/JSA107862 - Vendor Advisory
First Time Juniper apstra
Juniper
CWE NVD-CWE-Other
CPE cpe:2.3:a:juniper:apstra:*:*:*:*:*:*:*:*

09 Apr 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-09 22:16

Updated : 2026-07-08 03:18


NVD link : CVE-2025-13914

Mitre link : CVE-2025-13914

CVE.ORG link : CVE-2025-13914


JSON object : View

Products Affected

juniper

  • apstra
CWE
CWE-322

Key Exchange without Entity Authentication

NVD-CWE-Other