Networking equipment manufacturer Juniper has confirmed the existence
of the backdoor, which they call unauthorized code, in several of its
products. Outside researchers confirm the backdoor which was designed
to look like debug code. Juniper has released a list of affected
products.
https://community.rapid7.com/community/infosec/blog/2015/12/20/cve-2015-7755-juniper-screenos-authentication-backdoorIf your Juniper firewall is exposed to the
Internet and unmatched, then it is too late to patch now. Starting
Monday afternoon continuous exploit attempts were detected for this
vulnerability from multiple sources that appear to scan the internet for
vulnerable systems. The Internet Storm Center went to Infocon
"Yellow" on Monday to alert users of Juniper equipment of the imminent
danger after the backdoor password was revealed by Rapid7.