attacker to impersonate managed devices.
Due to insufficient SSH host key validation an attacker can perform a machine-in-the-middle attack on the SSH connections from Apstra to managed devices, enabling an attacker to impersonate a managed device and capture user credentials.
This issue affects all versions of Apstra before 6.1.1.
Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
The following software releases have been updated to resolve this specific issue: Apstra 6.1.1, and all subsequent releases.
Vendor Workaround
There are no known workarounds for this issue.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://kb.juniper.net/JSA107862 |
|
Tue, 14 Apr 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 10 Apr 2026 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Juniper Networks
Juniper Networks apstra |
|
| Vendors & Products |
Juniper Networks
Juniper Networks apstra |
Thu, 09 Apr 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A Key Exchange without Entity Authentication vulnerability in the SSH implementation of Juniper Networks Apstra allows a unauthenticated, MITM attacker to impersonate managed devices. Due to insufficient SSH host key validation an attacker can perform a machine-in-the-middle attack on the SSH connections from Apstra to managed devices, enabling an attacker to impersonate a managed device and capture user credentials. This issue affects all versions of Apstra before 6.1.1. | |
| Title | Apstra: SSH host key validation vulnerability for managed devices | |
| Weaknesses | CWE-322 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: juniper
Published:
Updated: 2026-04-14T14:35:15.915Z
Reserved: 2025-12-02T17:48:47.280Z
Link: CVE-2025-13914
Updated: 2026-04-14T14:35:12.542Z
Status : Awaiting Analysis
Published: 2026-04-09T22:16:22.697
Modified: 2026-04-13T15:02:27.760
Link: CVE-2025-13914
No data.
OpenCVE Enrichment
Updated: 2026-04-10T09:27:57Z