CVE-2019-0021
published 2019-01-15CVE-2019-0021: On Juniper ATP, secret passphrase CLI inputs, such as "set mcm", are logged to /var/log/syslog in clear text, allowing authenticated local user to be able to…
PriorityP423medium5.5CVSS 3.0
AVLACLPRLUINSUCHINAN
EPSS
0.34%
25.6th percentile
On Juniper ATP, secret passphrase CLI inputs, such as "set mcm", are logged to /var/log/syslog in clear text, allowing authenticated local user to be able to view these secret information. This issue affects Juniper ATP 5.0 versions prior to 5.0.4.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| juniper | advanced_threat_prevention | >= 5.0.0 < 5.0.4 | 5.0.4 |
| juniper_networks | juniper_atp | >= 5.0 < 5.0.4 | 5.0.4 |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
VMware Workstation and Fusion updates address multiple security vulnerabilities (CVE-2019-5540, CVE-2019-5541, CVE-2019-5542)
vendor_vmware·2019-11-12·CVSS 7.7
CVE-2019-5540 [HIGH] VMware Workstation and Fusion updates address multiple security vulnerabilities (CVE-2019-5540, CVE-2019-5541, CVE-2019-5542)
VMSA-2019-0021: VMware Workstation and Fusion updates address multiple security vulnerabilities (CVE-2019-5540, CVE-2019-5541, CVE-2019-5542)
| Advisory Severity | Important | CVSSv3 Range | 5.0-8.7 | Synopsis | VMware Workstation and Fusion updates address multiple security vulnerabilities (CVE-2019-5540, CVE-2019-5541, CVE-2019-5542) | Issue Date | 2019-11-12 | Updated On | 2019-11-12 (Initial Advisory) | CVE(s) | CVE-2019-5540, CVE-2019-5541, CVE-2019-5542 VMware Workstation Pro / Player (Workstation) VMware Fusion Pro / Fusion (Fusion)2. IntroductionVMware Workstation and Fusion contain multiple security vulnerabilities. Patches and workarounds are available to remediate these vulnerabilities in affected VMware products.
CVEs: CVE-2019-5540, CVE-2019-5541, CVE-2019-5542
Affected prod
Juniper
CVE-2019-0021: On Juniper ATP, secret passphrase CLI inputs, such as "set mcm", are logged to /var/log/syslog in clear text, allowing authenticated local user to be
vendor_juniper·2019-01-15·CVSS 7.1
CVE-2019-0021 [HIGH] CWE-532 CVE-2019-0021: On Juniper ATP, secret passphrase CLI inputs, such as "set mcm", are logged to /var/log/syslog in clear text, allowing authenticated local user to be
CVE-2019-0021: On Juniper ATP, secret passphrase CLI inputs, such as "set mcm", are logged to /var/log/syslog in clear text, allowing authenticated local user to be able to view these secret information. This issue affects Juniper ATP 5.0 versions prior to 5.0.4.
GHSA
GHSA-6cqx-g9mw-4p5m: On Juniper ATP, secret passphrase CLI inputs, such as "set mcm", are logged to /var/log/syslog in clear text, allowing authenticated local user to be
ghsa_unreviewed·2022-05-13
CVE-2019-0021 [MEDIUM] CWE-532 GHSA-6cqx-g9mw-4p5m: On Juniper ATP, secret passphrase CLI inputs, such as "set mcm", are logged to /var/log/syslog in clear text, allowing authenticated local user to be
On Juniper ATP, secret passphrase CLI inputs, such as "set mcm", are logged to /var/log/syslog in clear text, allowing authenticated local user to be able to view these secret information. This issue affects Juniper ATP 5.0 versions prior to 5.0.4.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2019-01-15
Published