SecurityWeek reports that Jupiter Networks, a networking hardware and software company, has issued patches for around 30 vulnerabilities in Junos OS and related systems.
The flaws include risks of privilege escalation, service disruption, and remote code execution. The most critical issue is a default password that enables remote compromise of devices, made more severe by weak password enforcement and an SSH (Secure Shell) flaw that allows credential interception via machine-in-the-middle (MITM) attacks. The company emphasized that vLWC software images ship with an initial password for a high-privileged account. A change of this password is not enforced during the provisioning of the software, which can make full access to the system by unauthorized actors possible.
No active exploitation has been detected so far, but Junos OS is affected by serious vulnerabilities that could allow attackers to bypass security controls, escalate privileges, disrupt services, and gain extensive or even full control of impacted network devices.
