{"id":"CVE-2025-13914","title":"A Key Exchange without Entity Authentication vulnerability in the SSH implementation of Juniper Networks Apstra allows a unauthenticated, MITM \n\nattacker to impersonate managed devices.\n\nDue to insufficient SSH host key validation an att…","summary":"A Key Exchange without Entity Authentication vulnerability in the SSH implementation of Juniper Networks Apstra allows a unauthenticated, MITM \n\nattacker to impersonate managed devices.\n\nDue to insufficient SSH host key validation an att…","severity":"high","cvss":8.7,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N","cwe":["CWE-322"],"vendor":"juniper","product":"apstra","affected":["apstra < 6.1.1"],"patched":["apstra 6.1.1"],"published":"2026-04-09","updated":"2026-07-08","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-13914","references":[{"url":"https://kb.juniper.net/JSA107862","label":"sirt@juniper.net"}],"tags":["nvd"],"epss":0.00303,"epssPercentile":0.23276,"ingestedAt":"2026-07-08T03:46:38.617Z","slug":"CVE-2025-13914","body":"## Overview\n\nA Key Exchange without Entity Authentication vulnerability in the SSH implementation of Juniper Networks Apstra allows a unauthenticated, MITM \n\nattacker to impersonate managed devices.\n\nDue to insufficient SSH host key validation an attacker can perform a machine-in-the-middle attack on the SSH connections from Apstra to managed devices, enabling an attacker to impersonate a managed device and capture user credentials.\n\nThis issue affects all versions of Apstra before 6.1.1.\n\n## Affected\n\n- `apstra < 6.1.1`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `apstra 6.1.1`","depth":"twilight","depthScore":48,"depthScoreParts":{"impact":47.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}