PT-2021-12945 · Juniper Networks · Paragon Active Assurance Control Center

Published

2021-04-22

·

Updated

2022-09-20

·

CVE-2021-0232

CVSS v3.1

7.4

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Juniper Networks Paragon Active Assurance Control Center versions prior to 2.35.6 Juniper Networks Paragon Active Assurance Control Center version 2.36 versions prior to 2.36.2
Description: An authentication bypass issue may allow an attacker with specific deployment information to mimic a registered Test Agent, accessing its configuration and associated inventory details. If the issue occurs, the affected Test Agent cannot connect to the Control Center.
Recommendations: For versions prior to 2.35.6, update to version 2.35.6 or later. For version 2.36 prior to 2.36.2, update to version 2.36.2 or later.

Fix

Authentication Bypass by Spoofing

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2021-0232

Affected Products

Paragon Active Assurance Control Center