CVE-2018-14366
Summary
| CVE | CVE-2018-14366 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-09-06 23:29:00 UTC |
| Updated | 2020-04-29 17:33:00 UTC |
| Description | download.cgi in Pulse Secure Pulse Connect Secure 8.1RX before 8.1R13 and 8.3RX before 8.3R4 and Pulse Policy Secure through 5.2RX before 5.2R10 and 5.4RX before 5.4R4 have an Open Redirect Vulnerability. |
Risk And Classification
Problem Types: CWE-601
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Pulsesecure | Pulse Connect Secure | 8.1 | All | All | All |
| Application | Pulsesecure | Pulse Connect Secure | 8.1r1.0 | All | All | All |
| Application | Pulsesecure | Pulse Connect Secure | 8.1rx | All | All | All |
| Application | Pulsesecure | Pulse Connect Secure | 8.3 | All | All | All |
| Application | Pulsesecure | Pulse Connect Secure | 8.3rx | All | All | All |
| Application | Pulsesecure | Pulse Connect Secure | 8.1 | All | All | All |
| Application | Pulsesecure | Pulse Connect Secure | 8.1r1.0 | All | All | All |
| Application | Pulsesecure | Pulse Connect Secure | 8.1rx | All | All | All |
| Application | Pulsesecure | Pulse Connect Secure | 8.3 | All | All | All |
| Application | Pulsesecure | Pulse Connect Secure | 8.3rx | All | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 5.2r1.0 | All | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 5.2r2.0 | All | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 5.2r3.0 | All | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 5.2r3.2 | All | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 5.2r4.0 | All | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 5.2r5.0 | All | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 5.2r6.0 | All | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 5.2r7.0 | All | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 5.2r7.1 | All | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 5.2r8.0 | All | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 5.2r9.0 | All | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 5.2r9.1 | All | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 5.2rx | All | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 5.4r1 | All | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 5.4r2 | All | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 5.4r2.1 | All | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 5.4r3 | All | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 5.4rx | All | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 5.2r1.0 | All | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 5.2r2.0 | All | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 5.2r3.0 | All | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 5.2r3.2 | All | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 5.2r4.0 | All | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 5.2r5.0 | All | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 5.2r6.0 | All | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 5.2r7.0 | All | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 5.2r7.1 | All | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 5.2r8.0 | All | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 5.2r9.0 | All | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 5.2r9.1 | All | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 5.2rx | All | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 5.4r1 | All | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 5.4r2 | All | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 5.4r2.1 | All | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 5.4r3 | All | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 5.4rx | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Public KB - SA43877 - 2018-08 Security Bulletin: Multiple vulnerabilities resolved in Pulse Connect Secure / Pulse Policy Secure / Pulse Secure Desktop 9.0R1/9.0R2 | CONFIRM | kb.pulsesecure.net | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.