Juniper Junos Space < 12.3P2.8 Password Disclosure (JSA10567)

medium Nessus Plugin ID 80191

Synopsis

The remote device is affected by a password disclosure vulnerability.

Description

According to its self-reported version number, the remote Junos Space version is prior to 12.3P2.8. It is, therefore, affected by a password disclosure vulnerability. When an authenticated user is viewing certain configuration pages in the interface, some passwords may be displayed in plaintext.

Solution

Upgrade to Junos Space 12.3P2.8 or later.

See Also

https://kb.juniper.net/InfoCenter/index?page=content&id=JSA10567

Plugin Details

Severity: Medium

ID: 80191

File Name: juniper_space_jsa10567.nasl

Version: 1.4

Type: local

Published: 12/22/2014

Updated: 7/12/2018

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.0

CVSS v2

Risk Factor: Medium

Base Score: 4.7

Temporal Score: 3.5

Vector: CVSS2#AV:L/AC:M/Au:N/C:C/I:N/A:N

Vulnerability Information

CPE: cpe:/a:juniper:junos_space

Required KB Items: Host/Junos_Space/version

Exploit Ease: No known exploits are available

Patch Publication Date: 5/10/2013

Vulnerability Publication Date: 5/8/2013

Reference Information

CVE: CVE-2013-3497

BID: 59760