CVE-2019-0020
published 2019-01-15CVE-2019-0020: Juniper ATP ships with hard coded credentials in the Web Collector instance which gives an attacker the ability to take full control of any installation of the…
PriorityP357critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
1.57%
72.5th percentile
Juniper ATP ships with hard coded credentials in the Web Collector instance which gives an attacker the ability to take full control of any installation of the software. Affected releases are Juniper Networks Juniper ATP: 5.0 versions prior to 5.0.3.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| juniper | advanced_threat_prevention | >= 5.0.0 < 5.0.3 | 5.0.3 |
| juniper_networks | juniper_atp | >= 5.0 < 5.0.3 | 5.0.3 |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-426w-g76x-326w: Juniper ATP ships with hard coded credentials in the Web Collector instance which gives an attacker the ability to take full control of any installati
ghsa_unreviewed·2022-05-13
CVE-2019-0020 [CRITICAL] CWE-798 GHSA-426w-g76x-326w: Juniper ATP ships with hard coded credentials in the Web Collector instance which gives an attacker the ability to take full control of any installati
Juniper ATP ships with hard coded credentials in the Web Collector instance which gives an attacker the ability to take full control of any installation of the software. Affected releases are Juniper Networks Juniper ATP: 5.0 versions prior to 5.0.3.
VMware
VMware ESXi, Workstation, and Fusion patches provide Hypervisor-Specific Mitigations for Denial-of-Service and Speculative-Execution Vulnerabilities (CVE-2018-12207, CVE-2019-11135)
vendor_vmware·2019-11-12·CVSS 6.5
CVE-2018-12207 [MEDIUM] VMware ESXi, Workstation, and Fusion patches provide Hypervisor-Specific Mitigations for Denial-of-Service and Speculative-Execution Vulnerabilities (CVE-2018-12207, CVE-2019-11135)
VMSA-2019-0020: VMware ESXi, Workstation, and Fusion patches provide Hypervisor-Specific Mitigations for Denial-of-Service and Speculative-Execution Vulnerabilities (CVE-2018-12207, CVE-2019-11135)
| Advisory Severity | Moderate | Synopsis | VMware ESXi, Workstation, and Fusion patches provide Hypervisor-Specific Mitigations for Denial-of-Service and Speculative-Execution Vulnerabilities (CVE-2018-12207, CVE-2019-11135) | Issue Date | 2019-11-12 | Updated On | 2019-11-12 (Initial Advisory) | CVE(s) | CVE-2018-12207, CVE-2019-11135
CVEs: CVE-2018-12207, CVE-2019-11135
Affected products: VMware ESXi, VMware Fusion, VMware Workstation, vSphere
Juniper
CVE-2019-0020: Juniper ATP ships with hard coded credentials in the Web Collector instance which gives an attacker the ability to take full control of any installati
vendor_juniper·2019-01-15·CVSS 10.0
CVE-2019-0020 [CRITICAL] CWE-798 CVE-2019-0020: Juniper ATP ships with hard coded credentials in the Web Collector instance which gives an attacker the ability to take full control of any installati
CVE-2019-0020: Juniper ATP ships with hard coded credentials in the Web Collector instance which gives an attacker the ability to take full control of any installation of the software. Affected releases are Juniper Networks Juniper ATP: 5.0 versions prior to 5.0.3.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2019-01-15
Published