CVE-2024-30381 HIGH

CVE-2024-30381: Paragon Active Assurance: probe_serviced exposes internal objects to local users

Vendor Juniper Networks
Product Paragon Active Assurance
Weakness CWE-200 · Info exposure
Published April 12, 2024
Last update August 2, 2024

CVSS base score

8.4/10
Attack vector Adjacent
Attack complexity Low
Privileges required High
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

What the vulnerability does

01Description

An Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Juniper Networks Paragon Active Assurance Control Center allows a network-adjacent attacker with root access to a Test Agent Appliance the ability to access sensitive information about downstream devices. The "netrounds-probe-login" daemon (also called probe_serviced) exposes functions where the Test Agent (TA) Appliance pushes interface state/config, unregister itself, etc. The remote service accidentally exposes an internal database object that can be used for direct database access on the Paragon Active Assurance Control Center. This issue affects Paragon Active Assurance: 4.1.0, 4.2.0.

Key dates

02Disclosure timeline

April 12, 2024 CVE published
August 2, 2024 Record updated