CVE-2021-0232

An authentication bypass vulnerability in the Juniper Networks Paragon Active Assurance Control Center may allow an attacker with specific information about the deployment to mimic an already registered Test Agent and access its configuration including associated inventory details. If the issue occurs, the affected Test Agent will not be able to connect to the Control Center. This issue affects Juniper Networks Paragon Active Assurance Control Center All versions prior to 2.35.6; 2.36 versions prior to 2.36.2.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:juniper:paragon_active_assurance_control_center:*:*:*:*:*:*:*:*
cpe:2.3:a:juniper:paragon_active_assurance_control_center:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*

History

07 Nov 2023, 03:27

Type Values Removed Values Added
References
  • {'url': 'https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TNPCV3KRDI5PLLLKADFVIOHACQJLZMLI/', 'name': 'FEDORA-2021-761cda0b77', 'tags': ['Mailing List', 'Third Party Advisory'], 'refsource': 'FEDORA'}
  • () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TNPCV3KRDI5PLLLKADFVIOHACQJLZMLI/ -

20 Sep 2022, 17:09

Type Values Removed Values Added
CWE CWE-668 CWE-290

31 Mar 2022, 16:53

Type Values Removed Values Added
References (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TNPCV3KRDI5PLLLKADFVIOHACQJLZMLI/ - (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TNPCV3KRDI5PLLLKADFVIOHACQJLZMLI/ - Mailing List, Third Party Advisory
CPE cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*
First Time Fedoraproject fedora
Fedoraproject

31 Dec 2021, 03:15

Type Values Removed Values Added
References
  • (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TNPCV3KRDI5PLLLKADFVIOHACQJLZMLI/ -

27 Apr 2021, 15:12

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : 5.8
v3 : 7.4
References (MISC) https://kb.juniper.net/JSA11127 - (MISC) https://kb.juniper.net/JSA11127 - Vendor Advisory
CPE cpe:2.3:a:juniper:paragon_active_assurance_control_center:*:*:*:*:*:*:*:*
CWE CWE-668

22 Apr 2021, 20:25

Type Values Removed Values Added
New CVE

Information

Published : 2021-04-22 20:15

Updated : 2023-12-10 13:55


NVD link : CVE-2021-0232

Mitre link : CVE-2021-0232

CVE.ORG link : CVE-2021-0232


JSON object : View

Products Affected

fedoraproject

  • fedora

juniper

  • paragon_active_assurance_control_center
CWE
CWE-290

Authentication Bypass by Spoofing

CWE-284

Improper Access Control