CVE-2024-21589

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Jan 12, 2024
Updated: Jan 19, 2024
CWE ID 284

Summary

CVE-2024-21589 is an Improper Access Control vulnerability affecting the Juniper Networks Paragon Active Assurance Control Center. This issue, present in versions 3.1.0, 3.2.0, 3.2.2, 3.3.0, 3.3.1, and 3.4.0, allows unauthenticated network attackers to gain access to reports, potentially containing sensitive configuration information. A misconfigured access control feature introduced in version 3.1.0 is the root cause, enabling attackers to bypass authentication requirements. The Paragon Active Assurance Control Center SaaS offering remains unaffected.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share