SB2024041101 - Information disclosure in Junos OS Evolved
Published: April 11, 2024
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Cleartext storage of sensitive information (CVE-ID: CVE-2024-30406)
CWE-ID: CWE-312 - Cleartext Storage of Sensitive Information
CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
The vulnerability allows a local user to gain access to sensitive information.
The vulnerability exists due to the Paragon Active Assurance Test Agent software installed on the ACX Series devices stored users credential in clear text. A local privileged user can read the file and obtain credentials of other users.
Remediation
Install update from vendor's website.