A local, authenticated user with shell can obtain the hashed values of login passwords and shared secrets via the EvoSharedObjStore. This issue affects all versions of Junos OS Evolved prior to 19.1R1.
The following software releases have been updated to resolve this specific issue: 19.1R1-EVO, 19.2R1-EVO, and all subsequent releases.
There are no viable workarounds for this issue.
| Product | Vulnerable range | Fixed version | Advisory |
|---|---|---|---|
| Juniper Networks Junos OS Evolved | >=unspecified<19.1R1-EVO | 19.1R1-EVO | advisory ↗ |