Executive brief
Juniper Networks Support Insights (JSI) Virtual Lightweight Collector (vLWC) is a tool used to collect and transmit diagnostic data from network devices. A security flaw exists where these systems ship with a default password for a high-privileged account that is not required to be changed during setup. An unauthorized person could use this known password over the network to gain full control of the device, potentially leading to data theft or disruption of network monitoring services.
Technical details
A Use of Default Password vulnerability (CWE-1393) exists in the Juniper Networks Support Insights (JSI) Virtual Lightweight Collector (vLWC). The software images ship with a pre-configured initial password for a high-privileged account, and the provisioning process does not enforce a password change. An unauthenticated attacker with network access to the vLWC can use these default credentials to gain full administrative access to the system. This issue affects all versions of vLWC prior to 3.0.94. Users are advised to upgrade to version 3.0.94 or later to remediate the vulnerability.
Affected products
- Juniper Networks Support Insights (JSI) Virtual Lightweight Collector (vLWC) All versions before 3.0.94
Timeline
- 2026-04-09: advisory: Initial advisory published by Juniper Networks