CVE-2021-0232 HIGH

CVE-2021-0232: Paragon Active Assurance: Authentication bypass vulnerability in Control Center

Vendor Juniper Networks
Product Paragon Active Assurance
Weakness CWE-284
Published April 22, 2021
Last update September 16, 2024

CVSS base score

7.4/10
Attack vector Network
Attack complexity High
Privileges required None
User interaction None
Confidentiality High
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H

What the vulnerability does

01Description

An authentication bypass vulnerability in the Juniper Networks Paragon Active Assurance Control Center may allow an attacker with specific information about the deployment to mimic an already registered Test Agent and access its configuration including associated inventory details. If the issue occurs, the affected Test Agent will not be able to connect to the Control Center. This issue affects Juniper Networks Paragon Active Assurance Control Center All versions prior to 2.35.6; 2.36 versions prior to 2.36.2.

Key dates

02Disclosure timeline

April 22, 2021 CVE published
September 16, 2024 Record updated