SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-1620

A local, authenticated user with shell can obtain the hashed values of login passwords via configd streamer log.

MEDIUM 5.5EPSS 0.32%

Does this matter?

Lower severity and a low EPSS score (0.32%). Track it; it rarely justifies an emergency change on its own.

Description

A local, authenticated user with shell can obtain the hashed values of login passwords via configd streamer log. This issue affects all versions of Junos OS Evolved prior to 19.3R1.

CVSS 3.1
5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS
0.32% probability · 24th percentile
CISA KEV
Not listed
Weakness
CWE-664, CWE-532
Affected
juniper/junos os evolved
Source
sirt@juniper.net

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.