CVE-2015-5369
Summary
| CVE | CVE-2015-5369 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2015-08-11 14:59:12 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | Pulse Connect Secure (aka PCS and formerly Juniper PCS) PSC6000, PCS6500, and MAG PSC360 8.1 before 8.1r5, 8.0 before 8.0r13, 7.4 before 7.4r13.5, and 7.1 before 7.1r22.2 and PPS 5.1 before 5.1R5 and 5.0 before 5.0R13, when Hardware Acceleration is enabled, does not properly validate the Finished TLS handshake message, which makes it easier for remote attackers to conduct man-in-the-middle attacks via a crafted Finished message. |
Risk And Classification
Primary CVSS: v2.0 4.3 from [email protected]
AV:N/AC:M/Au:N/C:N/I:P/A:N
Problem Types: CWE-17 | CWE-20 | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:M/Au:N/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Juniper | Mag Pcs360 | - | All | All | All |
| Hardware | Juniper | Pcs6000 | - | All | All | All |
| Hardware | Juniper | Pcs6500 | - | All | All | All |
| Application | Juniper | Pulse Connect Secure | 5.1 | All | All | All |
| Application | Juniper | Pulse Connect Secure | 7.1 | All | All | All |
| Application | Juniper | Pulse Connect Secure | 7.4 | All | All | All |
| Application | Juniper | Pulse Connect Secure | 8.0 | All | All | All |
| Application | Juniper | Pulse Connect Secure | 8.1 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Juniper Pulse Secure TCP Hardware Acceleration Flaw Lets Remote Users Access Data on the Target System - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| Juniper Networks - [Pulse Secure] TLS connection verification issue (CVE-2015-5369) - Knowledge Base | af854a3a-2127-422b-91ae-364da2661108 | kb.juniper.net | |
| Vivaldi Web Browser Community - 404 - Not Found | af854a3a-2127-422b-91ae-364da2661108 | vivaldi.net | |
| Public KB - SA40004 - [Pulse Secure] TLS connection verification issue (CVE-2015-5369) | af854a3a-2127-422b-91ae-364da2661108 | kb.pulsesecure.net | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.