PT-2019-1175 · Juniper Networks · Juniper Advanced Threat Prevention

Published

2019-01-09

·

Updated

2021-11-23

·

CVE-2019-0030

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Juniper Advanced Threat Prevention versions prior to 5.0.3
Description The issue is related to the use of the DES algorithm and a hardcoded salt for password hashing in Juniper Advanced Threat Prevention. This allows for trivial de-hashing of the password file contents, potentially enabling an attacker to access protected information.
Recommendations For versions prior to 5.0.3, update to version 5.0.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the password file contents until a patch is applied.

Fix

Information Disclosure

Use of a Broken Cryptographic Algorithm

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-00242
CVE-2019-0030

Affected Products

Juniper Advanced Threat Prevention