A local, authenticated user with shell can obtain the hashed values of login passwords via configd streamer log. This issue affects all versions of Junos OS Evolved prior to 19.3R1.
References
Link | Resource |
---|---|
https://kb.juniper.net/JSA11003 | Vendor Advisory |
Configurations
Information
Published : 2020-04-08 13:15
Updated : 2020-04-10 11:09
NVD link : CVE-2020-1620
Mitre link : CVE-2020-1620
JSON object : View
CWE
CWE-532
Insertion of Sensitive Information into Log File
Products Affected
juniper
- junos_os_evolved