A local, authenticated user with shell can obtain the hashed values of login passwords and shared secrets via the EvoSharedObjStore. This issue affects all versions of Junos OS Evolved prior to 19.1R1.
Solution:
Workaround:
The product does not maintain or incorrectly maintains control over a resource throughout its lifetime of creation, use, and release.
The product writes sensitive information to a log file.
Link | Tags |
---|---|
https://kb.juniper.net/JSA11003 | vendor advisory |