CVE-2020-1616
Summary
| CVE | CVE-2020-1616 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-04-08 20:15:00 UTC |
| Updated | 2020-04-14 18:53:00 UTC |
| Description | Due to insufficient server-side login attempt limit enforcement, a vulnerability in the SSH login service of Juniper Networks Juniper Advanced Threat Prevention (JATP) Series and Virtual JATP (vJATP) devices allows an unauthenticated, remote attacker to perform multiple login attempts in excess of the configured login attempt limit. Successful exploitation will allow the attacker to perform brute-force password attacks on the SSH service. This issue affects: Juniper Networks JATP and vJATP versions prior to 5.0.6.0. |
Risk And Classification
Problem Types: CWE-307
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Juniper | Advanced Threat Protection | All | All | All | All |
| Application | Juniper | Advanced Threat Protection | All | All | All | All |
| Application | Juniper | Virtual Advanced Threat Protection | All | All | All | All |
| Application | Juniper | Virtual Advanced Threat Protection | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 2020-04 Security Bulletin: JATP Series: JATP Is susceptible to slow brute force attacks on the SSH service. (CVE-2020-1616) - Juniper Networks | MISC | kb.juniper.net | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.