CVE-2020-1675 is a vulnerability in Juniper Networks Mist Cloud Ui
Published on October 16, 2020
Juniper Networks Mist Cloud UI: SAML authentication certificate vulnerability.
When Security Assertion Markup Language (SAML) authentication is enabled, Juniper Networks Mist Cloud UI might incorrectly process invalid authentication certificates which could allow a malicious network-based user to access unauthorized data. This issue affects all Juniper Networks Mist Cloud UI versions prior to September 2 2020.
Vulnerability Analysis
CVE-2020-1675 can be exploited with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to be low. considered to have a small impact on confidentiality and integrity and availability.
Weakness Type
Improper Check for Certificate Revocation
The software does not check or incorrectly checks the revocation status of a certificate, which may cause it to use a certificate that has been compromised. An improper check for certificate revocation is a far more serious flaw than related certificate failures. This is because the use of any revoked certificate is almost certainly malicious. The most common reason for certificate revocation is compromise of the system in question, with the result that no legitimate servers will be using a revoked certificate, unless they are sorely out of sync.
Products Associated with CVE-2020-1675
Want to know whenever a new CVE is published for Juniper Networks Mist Cloud Ui? stack.watch will email you.
Affected Versions
Juniper Networks MIST Cloud UI:- Version unspecified and below 09/02/2020 is affected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.