VulnerabilityModified
CVE-2020-1624
A local, authenticated user with shell can obtain the hashed values of login passwords and shared secrets via raw objmon configuration files.
MEDIUM 5.5EPSS 0.32%
Does this matter?
Lower severity and a low EPSS score (0.32%). Track it; it rarely justifies an emergency change on its own.
Description
A local, authenticated user with shell can obtain the hashed values of login passwords and shared secrets via raw objmon configuration files. This issue affects all versions of Junos OS Evolved prior to 19.1R1.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.32% probability · 24th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-532
- Affected
- juniper/junos os evolved
- Source
- sirt@juniper.net
References
- https://kb.juniper.net/JSA11003Vendor Advisory
- https://kb.juniper.net/JSA11003Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.