CVE-2020-1675
16.10.2020, 21:15
When Security Assertion Markup Language (SAML) authentication is enabled, Juniper Networks Mist Cloud UI might incorrectly process invalid authentication certificates which could allow a malicious network-based user to access unauthorized data. This issue affects all Juniper Networks Mist Cloud UI versions prior to September 2 2020.Enginsight
Vendor | Product | Version |
---|---|---|
juniper | mist_cloud_ui | 𝑥 < 2020-09-02 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-299 - Improper Check for Certificate RevocationThe software does not check or incorrectly checks the revocation status of a certificate, which may cause it to use a certificate that has been compromised.
- CWE-295 - Improper Certificate ValidationThe software does not validate, or incorrectly validates, a certificate.