CVE-2025-13914Disclosure(juniper / apstra)

LOWCVSS 8.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch juniper apstra systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A Key Exchange without Entity Authentication vulnerability in the SSH implementation of Juniper Networks Apstra allows a unauthenticated, MITM attacker to impersonate managed devices. Due to insufficient SSH host key validation an attacker can perform a machine-in-the-middle attack on the SSH connections from Apstra to managed devices, enabling an attacker to impersonate a managed device and capture user credentials. This issue affects all versions of Apstra before 6.1.1.

0.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-322

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • apstra

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-04-09); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
apstra

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-09: 2Mentions · 2026-04-10: 1Patch / Workaround · 2026-04-09: 1Patch / Workaround · 2026-04-10: 1Technical Details · 2026-04-09: 2Technical Details · 2026-04-10: 104-0904-10
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-092
Disclosure1Patch1
2026-04-101
Disclosure1
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2025-13914 A Key Exchange without Entity Authentication vulnerability in the SSH implementation of Juniper Networks Apstra allows a unauthenticated, MITM attacker to impersona… https://www.cve.org/CVERecord?id=CVE-2025-13914

    Post summary

    The post briefly discloses a new SSH key exchange vulnerability in Juniper Apstra that permits unauthenticated MITM impersonation, with no PoC, exploit, or patch details shared.

    00010221
    57.0K followersView on X
  • dbugs@ptdbugs
    Disclosure

    Apstra: SSH host key validation vulnerability for managed devices CVE: CVE-2025-13914 PT ID: PT-2026-31796 Vendor: Juniper networks Product: Apstra CVSS: 8.7 Credits: Juniper SIRT would like to acknowledge and thank the Federal Office for Information Security (BSI) for responsibly reporting this vulnerability. Description: A Key Exchange without Entity Authentication vulnerability in the SSH implementation of Juniper Networks Apstra allows a unauthenticated, MITM attacker to impersonate managed devices. Due to insufficient SSH host key validation an attacker can perform a machine-in-the-middle attack on the SSH connections from Apstra to managed devices, enabling an attacker to impersonate a managed device and capture user credentials. This issue affects all versions of Apstra before 6.1.1. References: • https://dbugs.ptsecurity.com/vulnerability/CVE-2025-13914 • https://kb.juniper.net/JSA107862 #dbugs_vuln

    Post summary

    Juniper Networks disclosed a CVE‑2025‑13914 SSH host key validation issue in Apstra that allows unauthenticated MITM attacks. Affected versions are prior to 6.1.1 and a vendor advisory with patch guidance is available.

    00000515
    788 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2025-13914: HIGH] Critical security flaw in Juniper Networks Apstra: a Key Exchange without Entity Authentication vulnerability allows MITM attacks. Update to version 6.1.1 to fix.#cve,CVE-2025-13914,#cybersecurity https://cvefind.com/CVE-2025-13914

    Post summary

    The message informs about a high‑severity Juniper Networks Apstra vulnerability enabling MITM attacks and directs users to upgrade to version 6.1.1 for a fix.

    00000130
    619 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appjuniperapstra---

Explore more