---
id: CVE-2025-13914
title: >-
  A Key Exchange without Entity Authentication vulnerability in the SSH
  implementation of Juniper Networks Apstra allows a unauthenticated, MITM 


  attacker to impersonate managed devices.


  Due to insufficient SSH host key validation an att…
summary: >-
  A Key Exchange without Entity Authentication vulnerability in the SSH
  implementation of Juniper Networks Apstra allows a unauthenticated, MITM 


  attacker to impersonate managed devices.


  Due to insufficient SSH host key validation an att…
severity: high
cvss: 8.7
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N'
cwe:
  - CWE-322
vendor: juniper
product: apstra
affected:
  - apstra < 6.1.1
patched:
  - apstra 6.1.1
published: '2026-04-09'
updated: '2026-07-08'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-13914'
references:
  - url: 'https://kb.juniper.net/JSA107862'
    label: sirt@juniper.net
tags:
  - nvd
epss: 0.00303
epssPercentile: 0.20565
ingestedAt: '2026-07-08T03:46:38.617Z'
---

## Overview

A Key Exchange without Entity Authentication vulnerability in the SSH implementation of Juniper Networks Apstra allows a unauthenticated, MITM 

attacker to impersonate managed devices.

Due to insufficient SSH host key validation an attacker can perform a machine-in-the-middle attack on the SSH connections from Apstra to managed devices, enabling an attacker to impersonate a managed device and capture user credentials.

This issue affects all versions of Apstra before 6.1.1.

## Affected

- `apstra < 6.1.1`

## Remediation

Upgrade past the affected range:

- `apstra 6.1.1`
