CVE-2024-30406
6.7
Vector
CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:P/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow more
CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:P/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow less
Source: sirt@juniper.net (Secondary)
Description
A Cleartext Storage in a File on Disk vulnerability in Juniper Networks Junos OS Evolved ACX Series devices using the Paragon Active Assurance Test Agent software installed on network devices allows a local, authenticated attacker with high privileges to read all other users login credentials.
This issue affects only Juniper Networks Junos OS Evolved ACX Series devices using the Paragon Active Assurance Test Agent software installed on these devices from 23.1R1-EVO through 23.2R2-EVO.
This issue does not affect releases before 23.1R1-EVO.
Affected (9)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 23.1 | |
| All versions |
| Running on/with | Platform Versions |
|---|---|
Juniper Acx5448 | All versions |
Juniper Acx5448 D | All versions |
Juniper Acx5448 M | All versions |
Juniper Acx7020 | All versions |
Juniper Acx7024 | All versions |
Juniper Acx7024x | All versions |
Juniper Acx710 | All versions |
Juniper Acx7100 | All versions |
Juniper Acx7300 | All versions |
Juniper Acx7509 | All versions |
References (8)
Source: sirt@juniper.net
Vendor Advisory
Source: sirt@juniper.net
Technical Description
Source: sirt@juniper.net
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Technical Description
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Timeline
No history available yet.