Vulnerability Name: | CVE-2020-1624 (CCN-179316) | ||||||||||||
Assigned: | 2019-11-04 | ||||||||||||
Published: | 2020-04-08 | ||||||||||||
Updated: | 2020-04-10 | ||||||||||||
Summary: | A local, authenticated user with shell can obtain the hashed values of login passwords and shared secrets via raw objmon configuration files. This issue affects all versions of Junos OS Evolved prior to 19.1R1. | ||||||||||||
CVSS v3 Severity: | 5.5 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N) 4.8 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C)
4.8 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 2.1 Low (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N)
| ||||||||||||
Vulnerability Type: | CWE-532 | ||||||||||||
Vulnerability Consequences: | Obtain Information | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2020-1624 Source: XF Type: UNKNOWN juniper-cve20201624-info-disc(179316) Source: CCN Type: Juniper Networks Security Bulletin JSA11003 Junos OS Evolved: Local log files accessible from the shell may leak sensitive information Source: CONFIRM Type: Vendor Advisory https://kb.juniper.net/JSA11003 | ||||||||||||
Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||||||
BACK |