CVE-2019-0021: Juniper ATP: secret CLI inputs are logged to /var/log/syslog in clear text
Published Jan 15, 2019
·Updated
On Juniper ATP, secret passphrase CLI inputs, such as "set mcm", are logged to /var/log/syslog in clear text, allowing authenticated local user to be able to view these secret information. This issue affects Juniper ATP 5.0 versions prior to 5.0.4.
Affected Software
3 affected components
Juniper Advanced Threat Prevention>=5.0.0<5.0.4
Juniper Atp400
Juniper Atp700
Remediation
Information
The following software release have been updated to resolve this specific issue: 5.0.4 and all subsequent releases.
It is also recommended to purge the affected log files and/or change the passphrase after the upgrade.
Event History
Jan 15, 2019
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2019-0021?
CVE-2019-0021 is classified as a moderate severity vulnerability due to the exposure of sensitive data in clear text.
2
How do I fix CVE-2019-0021?
To fix CVE-2019-0021, upgrade to Juniper ATP version 5.0.4 or later, which resolves the logging issue.
3
Who is affected by CVE-2019-0021?
CVE-2019-0021 affects users of Juniper Advanced Threat Prevention versions earlier than 5.0.4.
4
What type of data is exposed in CVE-2019-0021?
CVE-2019-0021 exposes secret passphrases and configurations logged in clear text.
5
Can an unauthenticated user exploit CVE-2019-0021?
No, only authenticated local users can exploit CVE-2019-0021 to view sensitive data.