VYPR
Unrated severityNVD Advisory· Published Jan 15, 2019· Updated Sep 16, 2024

Juniper ATP: secret CLI inputs are logged to /var/log/syslog in clear text

CVE-2019-0021

Description

On Juniper ATP, secret passphrase CLI inputs, such as "set mcm", are logged to /var/log/syslog in clear text, allowing authenticated local user to be able to view these secret information. This issue affects Juniper ATP 5.0 versions prior to 5.0.4.

Affected products

2
  • Zyxel/ATPllm-fuzzy
    Range: <5.0.4
  • Juniper Networks/Juniper ATPv5
    Range: 5.0

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.