On Juniper ATP, secret passphrase CLI inputs, such as "set mcm", are logged to /var/log/syslog in clear text, allowing authenticated local user to be able to view these secret information. This issue affects Juniper ATP 5.0 versions prior to 5.0.4.
Solution:
Workaround:
The product writes sensitive information to a log file.
Link | Tags |
---|---|
https://kb.juniper.net/JSA10918 | vendor advisory |