Executive brief
Juniper Networks Apstra, a platform used to manage and automate data center networks, contains a security flaw in how it connects to managed devices. An attacker positioned between Apstra and the network equipment can impersonate a legitimate device, potentially allowing them to steal administrative credentials and gain unauthorized access to network infrastructure. This could lead to a full compromise of managed network devices and significant operational disruption.
Technical details
A vulnerability exists in the SSH implementation of Juniper Networks Apstra due to insufficient SSH host key validation during the key exchange process (CWE-322). An unauthenticated attacker with network access between the Apstra controller and managed devices can perform a machine-in-the-middle (MITM) attack. By successfully impersonating a managed device, the attacker can intercept SSH traffic and capture user credentials used for device management. This issue affects all versions of Apstra prior to 6.1.1, where the fix was implemented.
Affected products
- Juniper Networks Apstra All versions before 6.1.1
Timeline
- 2026-04-09: advisory: Initial advisory published by Juniper Networks
- 2026-04-09: disclosed
- 2026-07-07: other: NVD last modified date