Skip to main content

CVE detail

CVE-2015-7756

The encryption implementation in Juniper ScreenOS 6.2.0r15 through 6.2.0r18, 6.3.0r12 before 6.3.0r12b, 6.3.0r13 before 6.3.0r13b, 6.3.0r14 before 6.3.0r14b, 6.3.0r15 before 6.3.0r15b, 6.3.0r16 before 6.3.0r16b, 6.3.0r17 before 6.3.0r17b, 6.3.0r18 before 6.3.0r18b, 6.3.0r19 before 6.3.0r19b, and 6.3.0r20 before 6.3.0r21 makes it easier for remote attackers to discover the plaintext content of VPN sessions by sniffing the network for ciphertext data and conducting an unspecified decryption attack.

CVSS 5.0 · MediumBuzz score 32.0

Buzz score

Why this CVE is surfacing

Buzz score total 32.0

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 24.0 · diversity 8.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Mention score
24.0
10 evidence mentions in the snapshot
Diversity score
8.0
3 sources across 1 categories
KEV score
0.0
No KEV entry observed
OTX score
0.0
0 OTX pulses
PoC score
0.0
0 repos · best confidence N/A
Best PoC traction
0
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
0
within the 30d window
Peak daily
0
highest bucket

Evidence

Source links by recency

Newest mentions first
10 source links · newest first
  • The U.S. House Oversight and Government Reform Committee is probing US Government Agencies over use of backdoored Juniper equipment. A number of US Government Agencies are concerned about the use of Juniper firewalls affected by the recently uncovered backdoor. The U.S. House Oversight and Government Reform Committee has sent letters to dozens of government agencies and departments asking […]

    newssecurityaffairs.comJan 27, 2016, 7:09 AM
  • The U.S. House Oversight and Government Reform Committee has sent out letters to dozens of government agencies asking them about the use and patching of vulnerable Juniper Networks products.

    newswww.securityweek.comJan 26, 2016, 10:19 AM
  • The owners of more than 1,500 Juniper Networks firewalls still haven’t applied patches designed to address recently discovered backdoors, an Internet scan conducted by a researcher has shown.

    newswww.securityweek.comJan 6, 2016, 5:39 PM
  • A honeypot set up by researchers at the SANS institute has shown that hackers have already attempted to exploit the Juniper backdoor. Shortly after Juniper posted the advisory related to the presence of unauthorized code in the OS of some of its Firewalls, HD Moore, the developer of the Rapid7′ Metasploit Framework, revealed that approximately 26,000 […]

    newssecurityaffairs.comDec 23, 2015, 7:02 AM
  • A honeypot set up by researchers has shown that attackers have already attempted to exploit a recently disclosed vulnerability that can be used to gain administrative access to Juniper Networks’ NetScreen firewalls.

    newswww.securityweek.comDec 22, 2015, 2:42 PM
  • SANS Institute’s Internet Storm Center has raised its infocon status – the status of the condition of the Internet infrastructure – from green to yellow, following the public revelation of two backdoors in Juniper’s NetScreen firewall devices, and the publication of the password that allows easy exploitation of one of them. SANS ISC CTO Johannes Ullrich added two more reasons behind this decision: “Juniper devices are popular, and many organizations depend on them to defend … More →

    newswww.helpnetsecurity.comDec 22, 2015, 1:54 PM
  • Who planted the Authentication Backdoor in the Juniper ScreenOS? Security experts are making their speculation, but interesting revelations are coming out. While the FBI is investigating the case searching for responsible for the introduction of a backdoor in a number of Juniper network devices, a number of speculation are circulating on the Internet. Juniper Networks is a […]

    newssecurityaffairs.comDec 22, 2015, 12:02 PM
  • Who planted the backdoors in Juniper’s firewalls?Help Net Security

    Who put the recently discovered “unauthorized code” in ScreenOS, which effectively opened a backdoor in Juniper’s NetScreen firewall devices and allowed attackers to decrypt VPN connections? Speculations abound, and all currently point to a state-sponsored intruder. Was it China? NetScreen Technologies, the company that created the aforementioned appliances and that was acquired by Juniper Networks in 2004, was founded by Chinese nationals. As Simon Sharwood pointed out, “it’s not hard to find evidence of ongoing … More →

    newswww.helpnetsecurity.comDec 21, 2015, 2:13 PM
  • Security experts have been analyzing the Juniper Networks firewall backdoors whose existence was brought to light last week, and they’ve discovered what appears to be the root cause for both the administrative access and VPN decryption issues.

    newswww.securityweek.comDec 21, 2015, 10:25 AM
  • Networking and security company Juniper Networks revealed on Thursday that it has identified a couple of serious vulnerabilities that can be exploited to gain administrative access to some firewalls and decrypt VPN traffic.

    newswww.securityweek.comDec 18, 2015, 9:57 AM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

0 repository references · best confidence N/A · max 0 stars
No public PoC repositories have been matched yet.

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence
  • CVE-2026-17616

    IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 Reverse Proxy in c…

    CVSS 6.8 · Medium
    1 mention
  • CVE-2026-18591

    A vulnerability was identified in Meesho Online Shopping App up to 20260607 on Android. Affected by this vulnerability is an unknown functionality of the component com.meesho.supp…

    CVSS 0.9 · Low
    6 mentions
  • CVE-2026-16213

    A security flaw has been discovered in Fantomas42 django-blog-zinnia up to 0.20. Affected by this vulnerability is an unknown functionality of the file zinnia/views/mixins/entry_p…

    CVSS 4.8 · Medium
    6 mentions
  • CVE-2026-14702

    A flaw has been found in zcaceres markdownify-mcp up to 1.1.0. This impacts the function saveToTempFile of the file src/Markdownify.ts of the component webpage-to-markdown/youtube…

    CVSS 1.1 · Low
    7 mentions
  • CVE-2026-49000

    An insecure password scheme refers to vulnerabilities arising from improper selection of encryption algorithms, inadequate key management, or flawed code implementation, which may…

    CVSS 7.0 · High
    1 mention
  • CVE-2026-7847

    A vulnerability was found in chatchat-space Langchain-Chatchat up to 0.3.1.3. The affected element is the function _get_file_id of the file libs/chatchat-server/chatchat/server/ap…

    CVSS 1.2 · Low
    6 mentions