CVE-2020-1622

A local, authenticated user with shell can obtain the hashed values of login passwords and shared secrets via the EvoSharedObjStore. This issue affects all versions of Junos OS Evolved prior to 19.1R1.
References
Link Resource
https://kb.juniper.net/JSA11003 Vendor Advisory
https://kb.juniper.net/JSA11003 Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:o:juniper:junos_os_evolved:*:*:*:*:*:*:*:*

History

21 Nov 2024, 05:11

Type Values Removed Values Added
References () https://kb.juniper.net/JSA11003 - Vendor Advisory () https://kb.juniper.net/JSA11003 - Vendor Advisory

Information

Published : 2020-04-08 20:15

Updated : 2024-11-21 05:11


NVD link : CVE-2020-1622

Mitre link : CVE-2020-1622

CVE.ORG link : CVE-2020-1622


JSON object : View

Products Affected

juniper

  • junos_os_evolved
CWE
CWE-664

Improper Control of a Resource Through its Lifetime

CWE-532

Insertion of Sensitive Information into Log File