Juniper Networks Junos OS and Junos OS Evolved RADIUS Client Password Aging Vulnerability

Vulnerability

A vulnerability in the RADIUS client of Juniper Networks Junos OS and Junos OS Evolved allows authenticated, network-based attackers to access devices without enforcing mandatory password changes. This issue affects devices that permit logins from users whose passwords have expired, as indicated by a RADIUS server rejection. The vulnerability arises because the policy requiring password updates is not applied, enabling access with correct but expired passwords. This issue impacts multiple versions across both Junos OS and Junos OS Evolved.

Impact

Exploitation of this vulnerability allows authenticated users to bypass password expiration policies, gaining unauthorized access to the device with expired passwords.

Added: Oct 9, 2025, 5:19 PM
Updated: Oct 9, 2025, 5:19 PM

Vulnerability Rating

Custom Algorithm
spread
6.8
impact
0.0
exploitability
4.9
remediation
7.7
relevance
0.6
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.