Back to overview

CVE-2019-0020

CRITICAL
10.0
CVSS 3.0
Description
Juniper ATP ships with hard coded credentials in the Web Collector instance which gives an attacker the ability to take full control of any installation of the software. Affected releases are Juniper Networks Juniper ATP: 5.0 versions prior to 5.0.3.

Metadata

CVE ID
CVE-2019-0020
State
PUBLISHED
Assigner
juniper
Reserved
2018-10-11 00:00 UTC
Published
2019-01-15 21:00 UTC
Last updated
2024-09-16 22:01 UTC
Primary CWE
CWE-798
CWE-798: Use of Hard-coded Credentials
Vendor / Product
Juniper Networks / Juniper ATP
Sources
cve.org  ·  NVD

Severity & Metrics

10.0 CRITICAL CVSS 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Affected products (1)
VendorProductPlatformVersions
Juniper Networks Juniper ATP 5.0 < 5.0.3
Weakness (CWE)
CWESourceDescription
CWE-798 cna CWE-798: Use of Hard-coded Credentials
CVSS scores (1)
ScoreSeverityVersionSourceVector
10.0 CRITICAL 3.0 cna CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Back to overview