CVE-2019-0021

Severity CVSS v4.0:
Pending analysis
Type:
CWE-532 Information Exposure Through Log Files
Publication date:
15/01/2019
Last modified:
09/10/2019

Description

On Juniper ATP, secret passphrase CLI inputs, such as "set mcm", are logged to /var/log/syslog in clear text, allowing authenticated local user to be able to view these secret information. This issue affects Juniper ATP 5.0 versions prior to 5.0.4.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:juniper:advanced_threat_prevention:*:*:*:*:*:*:*:* 5.0.0 (including) 5.0.4 (excluding)
cpe:2.3:h:juniper:atp400:-:*:*:*:*:*:*:*
cpe:2.3:h:juniper:atp700:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools