CVE-2019-0072 describes an Unprotected Storage of Credentials vulnerability in Juniper Networks SBR Carrier versions 8.4.1 prior to 8.4.1R13 and 8.5.0 prior to 8.5.0R4. This flaw allows a local attacker to access confidential information due to insecure handling of credentials during the identity and access management certificate generation process. Rated Medium severity with a CVSS score of 5.5, the vulnerability requires local access (AV:L, PR:L) but has low attack complexity (AC:L) and results in high confidentiality impact (C:H). There is no evidence of active exploitation, publicly available exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 8.4.1, < 8.4.1R13CPE match | cpe:2.3:a:juniper:sbr_carrier:*:*:*:*:*:*:*:* | ||
>= 8.5.0, < 8.5.0R4CPE match | cpe:2.3:a:juniper:sbr_carrier:*:*:*:*:*:*:*:* | ||
8.4.1CPE matchmatch criteria | cpe:2.3:a:juniper:sbr_carrier:8.4.1:-:*:*:*:*:*:* | ||
8.4.1CPE matchmatch criteria | cpe:2.3:a:juniper:sbr_carrier:8.4.1:r1:*:*:*:*:*:* | ||
8.5.0CPE matchmatch criteria | cpe:2.3:a:juniper:sbr_carrier:8.5.0:-:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.