CVE-2020-1620

A local, authenticated user with shell can obtain the hashed values of login passwords via configd streamer log. This issue affects all versions of Junos OS Evolved prior to 19.3R1.
References
Link Resource
https://kb.juniper.net/JSA11003 Vendor Advisory
https://kb.juniper.net/JSA11003 Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:o:juniper:junos_os_evolved:*:*:*:*:*:*:*:*

History

21 Nov 2024, 05:11

Type Values Removed Values Added
References () https://kb.juniper.net/JSA11003 - Vendor Advisory () https://kb.juniper.net/JSA11003 - Vendor Advisory

Information

Published : 2020-04-08 20:15

Updated : 2024-11-21 05:11


NVD link : CVE-2020-1620

Mitre link : CVE-2020-1620

CVE.ORG link : CVE-2020-1620


JSON object : View

Products Affected

juniper

  • junos_os_evolved
CWE
CWE-664

Improper Control of a Resource Through its Lifetime

CWE-532

Insertion of Sensitive Information into Log File