2020-04-08 15:06:35 -04:00
{
"CVE_data_meta" : {
"ASSIGNER" : "sirt@juniper.net" ,
"DATE_PUBLIC" : "2020-04-08T16:00:00.000Z" ,
"ID" : "CVE-2020-1622" ,
"STATE" : "PUBLIC" ,
"TITLE" : "Junos OS Evolved: EvoSharedObjStore may leak sensitive information"
} ,
"affects" : {
"vendor" : {
"vendor_data" : [
{
"product" : {
"product_data" : [
{
"product_name" : "Junos OS Evolved" ,
"version" : {
"version_data" : [
{
"version_affected" : "<" ,
"version_value" : "19.1R1-EVO"
}
]
}
}
]
} ,
"vendor_name" : "Juniper Networks"
}
]
}
} ,
"data_format" : "MITRE" ,
"data_type" : "CVE" ,
"data_version" : "4.0" ,
"description" : {
"description_data" : [
{
"lang" : "eng" ,
2020-04-10 00:01:28 +00:00
"value" : "A local, authenticated user with shell can obtain the hashed values of login passwords and shared secrets via the EvoSharedObjStore. This issue affects all versions of Junos OS Evolved prior to 19.1R1."
2020-04-08 15:06:35 -04:00
}
]
} ,
"exploit" : [
{
"lang" : "eng" ,
"value" : "Juniper SIRT is not aware of any malicious exploitation of this vulnerability."
}
] ,
"generator" : {
"engine" : "Vulnogram 0.0.9"
} ,
"impact" : {
"cvss" : {
"attackComplexity" : "LOW" ,
"attackVector" : "LOCAL" ,
"availabilityImpact" : "NONE" ,
"baseScore" : 5.5 ,
"baseSeverity" : "MEDIUM" ,
"confidentialityImpact" : "HIGH" ,
"integrityImpact" : "NONE" ,
"privilegesRequired" : "LOW" ,
"scope" : "UNCHANGED" ,
"userInteraction" : "NONE" ,
"vectorString" : "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" ,
"version" : "3.1"
}
} ,
"problemtype" : {
"problemtype_data" : [
{
"description" : [
{
"lang" : "eng" ,
"value" : "CWE-664 Improper Control of a Resource Through its Lifetime"
}
]
}
]
} ,
"references" : {
"reference_data" : [
{
2020-04-09 10:57:42 -04:00
"name" : "https://kb.juniper.net/JSA11003" ,
"refsource" : "CONFIRM" ,
"url" : "https://kb.juniper.net/JSA11003"
2020-04-08 15:06:35 -04:00
}
]
} ,
"solution" : [
{
"lang" : "eng" ,
"value" : "The following software releases have been updated to resolve this specific issue: 19.1R1-EVO, 19.2R1-EVO, and all subsequent releases.\n"
}
] ,
"source" : {
"advisory" : "JSA11003" ,
"defect" : [
"1406195"
] ,
"discovery" : "INTERNAL"
} ,
"work_around" : [
{
"lang" : "eng" ,
"value" : "There are no viable workarounds for this issue."
}
]
}