CVE-2019-0021: Juniper Advanced Threat Prevention

Medium severity, CVSS 5.5. EPSS: 0.3% chance of exploitation in the next 30 days.

On Juniper ATP, secret passphrase CLI inputs, such as "set mcm", are logged to /var/log/syslog in clear text, allowing authenticated local user to be able to view these secret information. This issue affects Juniper ATP 5.0 versions prior to 5.0.4.

Affected products

  • Juniper Advanced Threat Prevention: from 5.0.0, before 5.0.4 (fixed in 5.0.4)

Published 2019-01-15. Last modified 2026-06-17.