PT-2024-1141 · Juniper Networks · Paragon Active Assurance

Published

2024-01-10

·

Updated

2024-01-19

·

CVE-2024-21589

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Juniper Networks Paragon Active Assurance versions 3.1.0 through 3.4.0
Description An Improper Access Control issue allows an unauthenticated network-based attacker to access reports without authenticating, potentially containing sensitive configuration information. A feature introduced in version 3.1.0 of the Paragon Active Assurance Control Center allows users to selectively share account data, which can be exploited to access reports without being logged in, resulting in the opportunity for malicious exfiltration of user data.
Recommendations For versions 3.1.0 through 3.4.0, consider disabling the report sharing feature until a patch is available to prevent unauthorized access to sensitive information. Restrict access to the report handler component to minimize the risk of exploitation. Avoid using the selective account data sharing feature in the affected versions until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-00455
CVE-2024-21589

Affected Products

Paragon Active Assurance