CVE-2019-0032
A locally authenticated attacker who is able to access these stored plaintext credentials can use them to login to the Organization.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.44%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A password management issue exists where the Organization authentication username and password were stored in plaintext in log files. A locally authenticated attacker who is able to access these stored plaintext credentials can use them to login to the Organization. Affected products are: Juniper Networks Service Insight versions from 15.1R1, prior to 18.1R1. Service Now versions from 15.1R1, prior to 18.1R1.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.44% probability · 38th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-256, CWE-522, CWE-532
- Affected
- juniper/service insight · juniper/service now
- Source
- sirt@juniper.net
References
- http://www.securityfocus.com/bid/107885Third Party Advisory, VDB Entry
- https://kb.juniper.net/JSA10921Vendor Advisory
- https://kb.juniper.net/KB27572Release Notes, Vendor Advisory
- http://www.securityfocus.com/bid/107885Third Party Advisory, VDB Entry
- https://kb.juniper.net/JSA10921Vendor Advisory
- https://kb.juniper.net/KB27572Release Notes, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.