CVE-2025-13914HIGH 8.7EPSS p19.7%

CVE-2025-13914CVE-2025-13914

Description

A Key Exchange without Entity Authentication vulnerability in the SSH implementation of Juniper Networks Apstra allows a unauthenticated, MITM attacker to impersonate managed devices. Due to insufficient SSH host key validation an attacker can perform a machine-in-the-middle attack on the SSH connections from Apstra to managed devices, enabling an attacker to impersonate a managed device and capture user credentials. This issue affects all versions of Apstra before 6.1.1.

Scoring

CVSS 3.18.7 (HIGH)
VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N
EPSS0.28% probability of exploitation · percentile 19.7% · 2026-06-18T12:00:27Z
Published2026-04-09
Last modified2026-04-13

Underlying weaknesses· 1

CWE-322

References

  1. https://kb.juniper.net/JSA107862

1

TypeTargetConfidenceTier
WeaknessKey Exchange without Entity Authenticationcwe-3220%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2025-59968
CVE
CVE-2025-20163
CVE
CVE-2025-52950
CVE
Juniper ScreenOS Improper Authentication Vulnerability
CVE
CVE-2025-59978
CVE
CVE-2025-11625
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.