CVE-2019-0021 Information
Feb 14, 2021
cve
Description
On Juniper ATP secret passphrase CLI inputs such as \set mcm\ are logged to /var/log/syslog in clear text allowing authenticated local user to be able to view these secret information. This issue affects Juniper ATP 5.0 versions prior to 5.0.4.
CVSS Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Reference
https://kb.juniper.net/JSA10918
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
NONE
Base Score
NONE
Base Severity
5.5
Share on: