Vulnerability Name: | CVE-2021-0232 (CCN-199946) | ||||||||||||
Assigned: | 2020-10-27 | ||||||||||||
Published: | 2021-04-14 | ||||||||||||
Updated: | 2022-09-20 | ||||||||||||
Summary: | An authentication bypass vulnerability in the Juniper Networks Paragon Active Assurance Control Center may allow an attacker with specific information about the deployment to mimic an already registered Test Agent and access its configuration including associated inventory details. If the issue occurs, the affected Test Agent will not be able to connect to the Control Center. This issue affects Juniper Networks Paragon Active Assurance Control Center All versions prior to 2.35.6; 2.36 versions prior to 2.36.2. | ||||||||||||
CVSS v3 Severity: | 7.4 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H) 6.4 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H/E:U/RL:O/RC:C)
6.4 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 5.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:P)
| ||||||||||||
Vulnerability Type: | CWE-290 | ||||||||||||
Vulnerability Consequences: | Denial of Service | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2021-0232 Source: XF Type: UNKNOWN juniper-cve20210232-info-disc(199946) Source: CCN Type: Juniper Networks Security Bulletin JSA11127 Paragon Active Assurance: Authentication bypass vulnerability (CVE-2021-0232) Source: MISC Type: Vendor Advisory https://kb.juniper.net/JSA11127 Source: FEDORA Type: Mailing List, Third Party Advisory FEDORA-2021-761cda0b77 | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: ![]() | ||||||||||||
BACK |