CVE-2019-0030

Juniper ATP uses DES and a hardcoded salt for password hashing, allowing for trivial de-hashing of the password file contents. This issue affects Juniper ATP 5.0 versions prior to 5.0.3.

Published : 2019-01-15 21:29 Updated : 2019-10-09 23:43

4.0
CVSS Score More info
Score 4.0 / 10
4.0

CPE

There is no CPE for this CVE.

CWE

ID Name Description Links
CWE-326 Inadequate Encryption Strength The software stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required. CVE

Reference

Source Link
CONFIRM https://kb.juniper.net/JSA10918

History of changes

Date Event
2019-01-29 14:34
2019-01-15 21:29

New CVE