GPU VulnDB

Database/Control plane, storage & DevOps

Juniper Security Director Policy Enforcer: unauthenticated attacker can replace vSRX images pushed to VMware NSX

CVSS 8.5CVE-2025-11198Control plane, storage & DevOpscurated

Impact

Security Director Policy Enforcer accepts vSRX firewall images over the network without authentication. An attacker who can reach the management interface stages a modified image; the next time an operator runs a deployment, Policy Enforcer hands that image to VMware NSX and it is instantiated as a virtual firewall inside the virtualization fabric. On a GPU estate that fronts tenant traffic with NSX-deployed vSRX, this puts attacker-controlled code on the segmentation boundary itself - the component that is supposed to keep tenant east-west traffic apart - and it arrives through a trusted deployment action, so nothing looks anomalous to the operator who initiated it. Exploitation needs no credentials, only reachability plus a legitimate deployment that follows.

Who can reach it

Anyone who can reach Security Director Policy Enforcer over the network, unauthenticated. The payload only lands when a trusted user subsequently initiates a deployment to NSX, so the attack needs that one legitimate user action to complete.

What to do

Upgrade Policy Enforcer to 23.1R1 Hotpatch v3 or later per JSA103437; all earlier versions are affected. This is a management-appliance upgrade, not a fleet action - no GPU node drain is needed. Until it is applied, restrict network reach to the Policy Enforcer management interface and verify the integrity of any vSRX image deployed to NSX in the interim. Junos Space Security Director Insights is not affected.

References

Related entries

All Control plane, storage & DevOps entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.