{"api_version":"1","generated_at":"2026-07-24T19:43:19+00:00","cve":"CVE-2018-6374","urls":{"html":"https://cve.report/CVE-2018-6374","api":"https://cve.report/api/cve/CVE-2018-6374.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2018-6374","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2018-6374"},"summary":{"title":"CVE-2018-6374","description":"The GUI component (aka PulseUI) in Pulse Secure Desktop Linux clients before PULSE5.2R9.2 and 5.3.x before PULSE5.3R4.2 does not perform strict SSL Certificate Validation. This can lead to the manipulation of the Pulse Connection set.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2018-01-31 21:29:00","updated_at":"2018-02-24 21:37:00"},"problem_types":["CWE-295"],"metrics":[],"references":[{"url":"http://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA43620","name":"http://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA43620","refsource":"CONFIRM","tags":["Vendor Advisory"],"title":"Public KB - SA43620 - 2018-01 Out-Of-Cycle Advisory : Pulse Secure Desktop Linux Client - SSL Certificate Validation Issue","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/102908","name":"102908","refsource":"BID","tags":["Third Party Advisory","VDB Entry"],"title":"Pulse Secure Desktop Linux Client CVE-2018-6374 Man in the Middle Security Bypass Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2018-6374","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2018-6374","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2018","cve_id":"6374","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"pulsesecure","cpe5":"desktop_linux_client","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"6374","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"pulsesecure","cpe5":"desktop_linux_client","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2018-6374","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The GUI component (aka PulseUI) in Pulse Secure Desktop Linux clients before PULSE5.2R9.2 and 5.3.x before PULSE5.3R4.2 does not perform strict SSL Certificate Validation. This can lead to the manipulation of the Pulse Connection set."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"102908","refsource":"BID","url":"http://www.securityfocus.com/bid/102908"},{"name":"http://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA43620","refsource":"CONFIRM","url":"http://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA43620"}]}},"nvd":{"publishedDate":"2018-01-31 21:29:00","lastModifiedDate":"2018-02-24 21:37:00","problem_types":["CWE-295"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"LOW","baseScore":6.5,"baseSeverity":"MEDIUM"},"exploitabilityScore":3.9,"impactScore":2.5},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:P","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":6.4},"severity":"MEDIUM","exploitabilityScore":10,"impactScore":4.9,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:pulsesecure:desktop_linux_client:*:*:*:*:*:*:*:*","versionEndExcluding":"5.2r9.2","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:pulsesecure:desktop_linux_client:*:*:*:*:*:*:*:*","versionEndExcluding":"5.3r4.2","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2018","CveId":"6374","Ordinal":"122438","Title":"CVE-2018-6374","CVE":"CVE-2018-6374","Year":"2018"},"notes":[{"CveYear":"2018","CveId":"6374","Ordinal":"1","NoteData":"The GUI component (aka PulseUI) in Pulse Secure Desktop Linux clients before PULSE5.2R9.2 and 5.3.x before PULSE5.3R4.2 does not perform strict SSL Certificate Validation. This can lead to the manipulation of the Pulse Connection set.","Type":"Description","Title":null},{"CveYear":"2018","CveId":"6374","Ordinal":"2","NoteData":"2018-01-31","Type":"Other","Title":"Published"},{"CveYear":"2018","CveId":"6374","Ordinal":"3","NoteData":"2018-02-03","Type":"Other","Title":"Modified"}]}}}