Cleartext storage of sensitive Information in Junos Space Service Insight and Junos Space Service Now - CVE-2019-0032
Published: May 20, 2019
Vulnerability identifier: #VU18538
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H]
CVE-ID: CVE-2019-0032
CWE-ID: CWE-312
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to gain access to the unencrypted data storage.
The vulnerability exists due to store username and password in plaintext in log files. A locally authenticated attacker can gain access to the Organization and read, modify or delete sensitive data.
Affected software
Junos Space Service Insight
Junos Space Service Now
Junos Space Service Now
How to mitigate CVE-2019-0032
Install updates from vendor's website.
Junos Space Service Insight - update to 18.1R1
Junos Space Service Now - update to 18.1R1
Junos Space Service Now - update to 18.1R1