PT-2021-2113 · Juniper Networks · Juniper Networks Contrail Networking

Published

2021-01-13

·

Updated

2022-04-25

·

CVE-2021-0212

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Juniper Networks Contrail Networking versions prior to 1911.31
Description: The issue is related to an Information Exposure vulnerability in Juniper Networks Contrail Networking. It allows a locally authenticated attacker with file read access to retrieve administrator credentials stored in plaintext, thereby elevating their privileges over the system. This can lead to unauthorized access to protected information.
Recommendations: For versions prior to 1911.31, update to version 1911.31 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive files and administrator credentials to minimize the risk of exploitation.

Fix

Information Disclosure

Insufficiently Protected Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-00969
CVE-2021-0212

Affected Products

Juniper Networks Contrail Networking