CVE-2020-1623: Junos OS Evolved: ev.ops file may leak sensitive information
A local, authenticated user with shell can view sensitive configuration information via the ev.ops configuration file. This issue affects all versions of Junos OS Evolved prior to 19.2R1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Juniper Junos OS Evolvedto a version that resolves this vulnerability.Fixed in 19.2R1-EVO
Event History
Frequently Asked Questions
What is the severity of CVE-2020-1623?
CVE-2020-1623 has a medium severity level as it allows local authenticated users to access sensitive configuration data.
How do I fix CVE-2020-1623?
To fix CVE-2020-1623, upgrade to Junos OS Evolved version 19.2R1 or later.
Who is affected by CVE-2020-1623?
All users of Junos OS Evolved versions prior to 19.2R1 are vulnerable to CVE-2020-1623.
What kind of information can be exposed by CVE-2020-1623?
CVE-2020-1623 can expose sensitive configuration information contained in the ev.ops file.
Is CVE-2020-1623 a remote access vulnerability?
No, CVE-2020-1623 requires local authenticated access to exploit the vulnerability.