Exposure of sensitive information to an unauthorized actor in Junos OS and Junos OS Evolved - CVE-2025-30654

 

Exposure of sensitive information to an unauthorized actor in Junos OS and Junos OS Evolved - CVE-2025-30654

Published: May 1, 2025


Vulnerability identifier: #VU108100
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-30654
CWE-ID: CWE-200
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to gain access to sensitive information.

The vulnerability exists due to exposure of sensitive information to an unauthorized actor error in the User Interface (UI). A local user can access sensitive information.

 Through the execution of a specific show mgd command, a user with limited permissions (for example, a low-privileged login class user) can access sensitive information such as hashed passwords, that can be used to further impact the system.


Affected software

Junos OS
Junos OS Evolved

How to mitigate CVE-2025-30654

Install updates from vendor's website.

Junos OS - addressed in versions 21.4R3-S10, 22.2R3-S6, 22.4R3-S5
Junos OS Evolved - update to 22.4R3-S5-EVO

External References

Related Security Bulletins