Back

MEDIUM

Junos OS: NFX350: Password hashes stored in world-readable format

Published Oct 16, 2020

Description

The Juniper Device Manager (JDM) container, used by the disaggregated Junos OS architecture on Juniper Networks NFX350 Series devices, stores password hashes in the world-readable file /etc/passwd. This is not a security best current practice as it can allow an attacker with access to the local filesystem the ability to brute-force decrypt password hashes stored on the system. This issue affects Juniper Networks Junos OS on NFX350: 19.4 versions prior to 19.4R3; 20.1 versions prior to 20.1R1-S4, 20.1R2.

Affected products

Remediation

Vendor solution

Junos OS now stores local password hashes in the protected /etc/shadow file.

The following software releases have been updated to resolve this specific issue: Junos OS 19.4R3, 20.1R1-S4, 20.1R2, 20.2R1, and all subsequent releases.

References (2)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner juniper
Published Oct 16, 2020
Updated Sep 17, 2024
Reserved Nov 4, 2019

CISA Vulnrichment

No data

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

No data

ENISA EUVD

Assigner juniper
Published Oct 16, 2020
Updated Sep 17, 2024

GitHub

No data