CVE-2019-0021: Juniper Advanced Threat Prevention
Medium severity, CVSS 5.5. EPSS: 0.3% chance of exploitation in the next 30 days.
On Juniper ATP, secret passphrase CLI inputs, such as "set mcm", are logged to /var/log/syslog in clear text, allowing authenticated local user to be able to view these secret information. This issue affects Juniper ATP 5.0 versions prior to 5.0.4.
Affected products
- Juniper Advanced Threat Prevention: from 5.0.0, before 5.0.4 (fixed in 5.0.4)
Published 2019-01-15. Last modified 2026-06-17.