The Juniper Device Manager (JDM) container, used by the disaggregated Junos OS architecture on Juniper Networks NFX350 Series devices, stores password hashes in the world-readable file /etc/passwd. This is not a security best current practice as it can allow an attacker with access to the local filesystem the ability to brute-force decrypt password hashes stored on the system. This issue affects Juniper Networks Junos OS on NFX350: 19.4 versions prior to 19.4R3; 20.1 versions prior to 20.1R1-S4, 20.1R2.
2020-10-16T21:15:12.880
2024-11-21T05:11:07.487
Modified
CVSSv3.1: 6.3 (MEDIUM)
AV:L/AC:L/Au:N/C:P/I:N/A:N
3.9
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | juniper | junos | 19.4 | Yes |
Operating System | juniper | junos | 19.4 | Yes |
Operating System | juniper | junos | 19.4 | Yes |
Operating System | juniper | junos | 19.4 | Yes |
Operating System | juniper | junos | 20.1 | Yes |
Operating System | juniper | junos | 20.1 | Yes |
Operating System | juniper | junos | 20.1 | Yes |
Operating System | juniper | junos | 20.1 | Yes |
Hardware | juniper | nfx350 | - | No |