Junos OS Evolved: EvoSharedObjStore may leak sensitive information
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 5.5epss 0.3%
exploitation probability
0.3%top 76% of all CVEs
observed exploitation
nono source reports it
A local, authenticated user with shell can obtain the hashed values of login passwords and shared secrets via the EvoSharedObjStore. This issue affects all versions of Junos OS Evolved prior to 19.1R1.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Affected products
Juniper Networks · Junos OS EvolvedReferences
https://kb.juniper.net/JSA11003