CVE-2024-30406
MEDIUMDescription
A Cleartext Storage in a File on Disk vulnerability in Juniper Networks Junos OS Evolved ACX Series devices using the Paragon Active Assurance Test Agent software installed on network devices allows a local, authenticated attacker with high privileges to read all other users login credentials. This issue affects only Juniper Networks Junos OS Evolved ACX Series devices using the Paragon Active Assurance Test Agent software installed on these devices from 23.1R1-EVO through 23.2R2-EVO. This issue does not affect releases before 23.1R1-EVO.
Is your site exposed to CVE-2024-30406?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| juniper | paragon_active_assurance_test_agent |
| juniper | junos_os_evolved |
| juniper | junos_os_evolved |
| juniper | junos_os_evolved |
| juniper | junos_os_evolved |
| juniper | junos_os_evolved |
| juniper | junos_os_evolved |
| juniper | junos_os_evolved |
| juniper | junos_os_evolved |
| juniper | acx5448 |
| juniper | acx5448-d |
| juniper | acx5448-m |
| juniper | acx7020 |
| juniper | acx7024 |
| juniper | acx7024x |
| juniper | acx710 |
| juniper | acx7100 |
| juniper | acx7300 |
| juniper | acx7509 |
References
Advisories & Patches
Other References
Frequently Asked Questions
What is CVE-2024-30406? +
How severe is CVE-2024-30406? +
What products are affected by CVE-2024-30406? +
How do I check if I'm vulnerable to CVE-2024-30406? +
Related Vulnerabilities
Puppet resource_api (shipped in Puppet Core 8.x and Puppet Enterprise 2023.8.x and 2025.x) does not preserve the sensitive flag on …
PrinterShare Android application allows the capture of Gmail authentication tokens that can be reused to access a user's Gmail account …
OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, OpenProject's Storages module writes the OneDrive/SharePoint userless OAuth …
A vulnerability has been identified in SIMATIC WinCC Unified PC Runtime V16 (All versions), SIMATIC WinCC Unified PC Runtime V17 …
Medtronic MyCareLink Patient Monitor uses per-product credentials that are stored in a recoverable format. An attacker can use these credentials …
A vulnerability in the Cisco Nexus Dashboard Fabric Controller (NDFC) software, formerly Cisco Data Center Network Manager (DCNM), could allow …