Back to overview

CVE-2026-33784

CRITICAL
9.8
CVSS 3.1
Description
A Use of Default Password vulnerability in the Juniper Networks Support Insights (JSI) Virtual Lightweight Collector (vLWC) allows an unauthenticated, network-based attacker to take full control of the device. vLWC software images ship with an initial password for a high privileged account. A change of this password is not enforced during the provisioning of the software, which can make full access to the system by unauthorized actors possible.This issue affects all versions of vLWC before 3.0.94.

Metadata

CVE ID
CVE-2026-33784
State
PUBLISHED
Assigner
juniper
Reserved
2026-03-23 19:46 UTC
Published
2026-04-09 21:36 UTC
Last updated
2026-04-13 18:06 UTC
Primary CWE
CWE-1393
CWE-1393 Use of Default Password
Vendor / Product
Juniper Networks / JSI LWC
Sources
cve.org  ·  NVD

Severity & Metrics

9.8 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
none
Automatable
no
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
Juniper Networks JSI LWC vLWC 0 < 3.0.94
Weakness (CWE)
CWESourceDescription
CWE-1393 cna CWE-1393 Use of Default Password
CVSS scores (2)
ScoreSeverityVersionSourceVector
9.8 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
9.3 CRITICAL 4.0 cna CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:L/AU:Y/R:U/RE:L
Back to overview