Database/Control plane, storage & DevOps
Juniper Security Director Policy Enforcer: unauthenticated attacker can replace vSRX images pushed to VMware NSX
Impact
Security Director Policy Enforcer accepts vSRX firewall images over the network without authentication. An attacker who can reach the management interface stages a modified image; the next time an operator runs a deployment, Policy Enforcer hands that image to VMware NSX and it is instantiated as a virtual firewall inside the virtualization fabric. On a GPU estate that fronts tenant traffic with NSX-deployed vSRX, this puts attacker-controlled code on the segmentation boundary itself - the component that is supposed to keep tenant east-west traffic apart - and it arrives through a trusted deployment action, so nothing looks anomalous to the operator who initiated it. Exploitation needs no credentials, only reachability plus a legitimate deployment that follows.
Who can reach it
Anyone who can reach Security Director Policy Enforcer over the network, unauthenticated. The payload only lands when a trusted user subsequently initiates a deployment to NSX, so the attack needs that one legitimate user action to complete.
What to do
Upgrade Policy Enforcer to 23.1R1 Hotpatch v3 or later per JSA103437; all earlier versions are affected. This is a management-appliance upgrade, not a fleet action - no GPU node drain is needed. Until it is applied, restrict network reach to the Policy Enforcer management interface and verify the integrity of any vSRX image deployed to NSX in the interim. Junos Space Security Director Insights is not affected.
References
Related entries
- VMware Aria Operations for Logs (credential disclosure): A View Only Admin reads the credentials of other VMwareCVE-2025-22218 · VMware Aria Operations for Logs (credential disclosure)High
- VMware vCenter (SMTP header injection via scheduled tasks): A non-administrative user with scheduled-task permissionsCVE-2025-41250 · VMware vCenter (SMTP header injection via scheduled tasks)High
- AMD NBIO register lock bits - System Management Network access: NBIO registers that should be locked after boot areCVE-2025-61972 · AMD NBIO register lock bits - System Management Network accessHigh
- Pure Storage FlashBlade logging: Sensitive material ends up in FlashBlade logs under certain conditions, and the scoredCVE-2026-0207 · Pure Storage FlashBlade loggingHigh
- GitLab package registry: authenticated path traversal that can lead to remote code executionCVE-2026-10053 · GitLab CE/EE package registryHigh
- GitLab: developer-role user can run pipelines on a protected branch without push rightsCVE-2026-15423 · GitLab CE/EE (CI/CD pipeline reference authorization)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.