ZeroHour

CVE-2018-6374

CVSS 3.0
6.5 medium
EPSS
<1%p47
Published
()
Modified
Description

The GUI component (aka PulseUI) in Pulse Secure Desktop Linux clients before PULSE5.2R9.2 and 5.3.x before PULSE5.3R4.2 does not perform strict SSL Certificate Validation. This can lead to the manipulation of the Pulse Connection set.

Vendors
pulsesecure
Products
desktop linux client
Weakness
CWE-295
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L

In the news

No ingested article mentions this CVE yet.