SB2024041101 - Information disclosure in Junos OS Evolved



SB2024041101 - Information disclosure in Junos OS Evolved

Published: April 11, 2024

Security Bulletin ID SB2024041101
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Information disclosure

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Cleartext storage of sensitive information (CVE-ID: CVE-2024-30406)

The vulnerability allows a local user to gain access to sensitive information.

The vulnerability exists due to the Paragon Active Assurance Test Agent software installed on the ACX Series devices stored users credential in clear text. A local privileged user can read the file and obtain credentials of other users.


Remediation

Install update from vendor's website.