A local, authenticated user with shell can obtain the hashed values of login passwords via configd streamer log. This issue affects all versions of Junos OS Evolved prior to 19.3R1.
The following software releases have been updated to resolve this specific issue: 19.3R1-EVO and all subsequent releases.
There are no viable workarounds for this issue.
| Product | Vulnerable range | Fixed version | Advisory |
|---|---|---|---|
| Juniper Networks Junos OS Evolved | >=unspecified<19.3R1-EVO | 19.3R1-EVO | advisory ↗ |