First published: Wed Oct 09 2019(Updated: )
An Unprotected Storage of Credentials vulnerability in the identity and access management certificate generation procedure allows a local attacker to gain access to confidential information. This issue affects: Juniper Networks SBR Carrier: 8.4.1 versions prior to 8.4.1R13; 8.5.0 versions prior to 8.5.0R4.
Credit: sirt@juniper.net
Affected Software | Affected Version | How to fix |
---|---|---|
Juniper Steel-Belted Radius Carrier | =8.4.1 | |
Juniper Steel-Belted Radius Carrier | =8.4.1-r1 | |
Juniper Steel-Belted Radius Carrier | =8.5.0 | |
Juniper Steel-Belted Radius Carrier | =8.5.0-r1 |
The following software releases have been updated to resolve this specific issue: 8.4.1R13, 8.5.0R4 and all subsequent releases.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-0072 is classified as a medium severity vulnerability due to its potential to expose confidential information.
To remediate CVE-2019-0072, upgrade to Juniper SBR Carrier version 8.4.1R13 or 8.5.0R1 or later.
CVE-2019-0072 affects Juniper Networks SBR Carrier versions 8.4.1 prior to 8.4.1R13 and version 8.5.0 prior to 8.5.0R1.
CVE-2019-0072 is an Unprotected Storage of Credentials vulnerability.
CVE-2019-0072 requires local access, making it less likely to be exploited remotely.