CVE-2018-6374
Summary
| CVE | CVE-2018-6374 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-01-31 21:29:00 UTC |
| Updated | 2018-02-24 21:37:00 UTC |
| Description | The GUI component (aka PulseUI) in Pulse Secure Desktop Linux clients before PULSE5.2R9.2 and 5.3.x before PULSE5.3R4.2 does not perform strict SSL Certificate Validation. This can lead to the manipulation of the Pulse Connection set. |
Risk And Classification
Problem Types: CWE-295
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Pulsesecure | Desktop Linux Client | All | All | All | All |
| Application | Pulsesecure | Desktop Linux Client | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Public KB - SA43620 - 2018-01 Out-Of-Cycle Advisory : Pulse Secure Desktop Linux Client - SSL Certificate Validation Issue | CONFIRM | kb.pulsesecure.net | Vendor Advisory |
| Pulse Secure Desktop Linux Client CVE-2018-6374 Man in the Middle Security Bypass Vulnerability | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.