imPC@ndo IT

Tracker / CVE-2013-3497

CVE-2013-3497

Medium 4.7

Juniper Junos Space before 12.3P2.8, as used on the JA1500 appliance and in other contexts, includes a cleartext password in a configuration tab, which makes it easier for physically proximate attackers to obtain the password by reading the workstation screen.

Affected products and versions

juniper junos_space
juniper junos_space · … → 12.3
juniper junos_space_ja1500_appliance
juniper junos_space_virtual_appliance

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References