Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Juniper ATP: secret CLI inputs are logged to /var/log/syslog in clear text
Vulnerability Description
On Juniper ATP, secret passphrase CLI inputs, such as "set mcm", are logged to /var/log/syslog in clear text, allowing authenticated local user to be able to view these secret information. This issue affects Juniper ATP 5.0 versions prior to 5.0.4.
CVSS Information
N/A
Vulnerability Type
通过日志文件的信息暴露
Vulnerability Title
Juniper ATP 安全漏洞
Vulnerability Description
Juniper Advanced Threat Prevention(ATP)是美国瞻博网络(Juniper Networks)公司的一套高级威胁防护平台。该产品支持恶意软件检测、文件分析、恶意IP地址和URL拦截等功能。 Juniper ATP 5.0.3之前的5.0版本中存在安全漏洞,该漏洞源于程序将敏感信息(例如:set mcm)以明文形式记录到/var/log/syslog中。本地攻击者可利用该漏洞查看敏感信息。
CVSS Information
N/A
Vulnerability Type
N/A