4.3

CVE-2015-5369

Pulse Connect Secure (aka PCS and formerly Juniper PCS) PSC6000, PCS6500, and MAG PSC360 8.1 before 8.1r5, 8.0 before 8.0r13, 7.4 before 7.4r13.5, and 7.1 before 7.1r22.2 and PPS 5.1 before 5.1R5 and 5.0 before 5.0R13, when Hardware Acceleration is enabled, does not properly validate the Finished TLS handshake message, which makes it easier for remote attackers to conduct man-in-the-middle attacks via a crafted Finished message.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
JuniperPulse Connect Secure Version5.1
   JuniperMag Pcs360 Version-
   JuniperPcs6000 Version-
   JuniperPcs6500 Version-
JuniperPulse Connect Secure Version7.1
   JuniperMag Pcs360 Version-
   JuniperPcs6000 Version-
   JuniperPcs6500 Version-
JuniperPulse Connect Secure Version7.4
   JuniperMag Pcs360 Version-
   JuniperPcs6000 Version-
   JuniperPcs6500 Version-
JuniperPulse Connect Secure Version8.0
   JuniperMag Pcs360 Version-
   JuniperPcs6000 Version-
   JuniperPcs6500 Version-
JuniperPulse Connect Secure Version8.1
   JuniperMag Pcs360 Version-
   JuniperPcs6000 Version-
   JuniperPcs6500 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.38% 0.584
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.