Lucene search

K
cvelistJuniperCVELIST:CVE-2021-0232
HistoryApr 22, 2021 - 7:37 p.m.

CVE-2021-0232 Paragon Active Assurance: Authentication bypass vulnerability in Control Center

2021-04-2219:37:00
CWE-284
juniper
www.cve.org
4
cve-2021-0232
juniper networks
authentication bypass
control center
vulnerability
deployment
configuration access

CVSS3

7.4

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H

AI Score

7.6

Confidence

High

EPSS

0.002

Percentile

64.7%

An authentication bypass vulnerability in the Juniper Networks Paragon Active Assurance Control Center may allow an attacker with specific information about the deployment to mimic an already registered Test Agent and access its configuration including associated inventory details. If the issue occurs, the affected Test Agent will not be able to connect to the Control Center. This issue affects Juniper Networks Paragon Active Assurance Control Center All versions prior to 2.35.6; 2.36 versions prior to 2.36.2.

CNA Affected

[
  {
    "platforms": [
      "Paragon Active Assurance Control Center"
    ],
    "product": "Paragon Active Assurance",
    "vendor": "Juniper Networks",
    "versions": [
      {
        "lessThan": "2.35.6",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      },
      {
        "lessThan": "2.36.2",
        "status": "affected",
        "version": "2.36",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

7.4

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H

AI Score

7.6

Confidence

High

EPSS

0.002

Percentile

64.7%

Related for CVELIST:CVE-2021-0232