7.5

CVE-2018-20812

An information exposure issue where IPv6 DNS traffic would be sent outside of the VPN tunnel (when Traffic Enforcement was enabled) exists in Pulse Secure Pulse Secure Desktop 9.0R1 and below. This is applicable only to dual-stack (IPv4/IPv6) endpoints.

Data is provided by the National Vulnerability Database (NVD)
PulsesecurePulse Secure Desktop Client Version4.0 Updater1.0 SwPlatformmac_os_x
PulsesecurePulse Secure Desktop Client Version4.0 Updater10.0 SwPlatformmac_os_x
PulsesecurePulse Secure Desktop Client Version4.0 Updater11.0 SwPlatformmac_os_x
PulsesecurePulse Secure Desktop Client Version4.0 Updater11.1 SwPlatformmac_os_x
PulsesecurePulse Secure Desktop Client Version4.0 Updater12.0 SwPlatformmac_os_x
PulsesecurePulse Secure Desktop Client Version4.0 Updater13.0 SwPlatformmac_os_x
PulsesecurePulse Secure Desktop Client Version4.0 Updater2.0 SwPlatformmac_os_x
PulsesecurePulse Secure Desktop Client Version4.0 Updater3.0 SwPlatformmac_os_x
PulsesecurePulse Secure Desktop Client Version4.0 Updater4.0 SwPlatformmac_os_x
PulsesecurePulse Secure Desktop Client Version4.0 Updater5.0 SwPlatformmac_os_x
PulsesecurePulse Secure Desktop Client Version4.0 Updater6.0 SwPlatformmac_os_x
PulsesecurePulse Secure Desktop Client Version4.0 Updater7.0 SwPlatformmac_os_x
PulsesecurePulse Secure Desktop Client Version4.0 Updater8.0 SwPlatformmac_os_x
PulsesecurePulse Secure Desktop Client Version4.0 Updater9.0 SwPlatformmac_os_x
PulsesecurePulse Secure Desktop Client Version4.0 Updater9.1 SwPlatformmac_os_x
PulsesecurePulse Secure Desktop Client Version4.0 Updater9.2 SwPlatformmac_os_x
PulsesecurePulse Secure Desktop Client Version5.1 Updater1.0 SwPlatformmacos
PulsesecurePulse Secure Desktop Client Version5.1 Updater1.1 SwPlatformmacos
PulsesecurePulse Secure Desktop Client Version5.1 Updater10.0 SwPlatformmacos
PulsesecurePulse Secure Desktop Client Version5.1 Updater11.0 SwPlatformmacos
PulsesecurePulse Secure Desktop Client Version5.1 Updater11.1 SwPlatformmacos
PulsesecurePulse Secure Desktop Client Version5.1 Updater12.0 SwPlatformmacos
PulsesecurePulse Secure Desktop Client Version5.1 Updater13.0 SwPlatformmacos
PulsesecurePulse Secure Desktop Client Version5.1 Updater14.0 SwPlatformmacos
PulsesecurePulse Secure Desktop Client Version5.1 Updater2.0 SwPlatformmacos
PulsesecurePulse Secure Desktop Client Version5.1 Updater3.0 SwPlatformmacos
PulsesecurePulse Secure Desktop Client Version5.1 Updater3.1 SwPlatformmacos
PulsesecurePulse Secure Desktop Client Version5.1 Updater4.0 SwPlatformmacos
PulsesecurePulse Secure Desktop Client Version5.1 Updater5.1 SwPlatformmacos
PulsesecurePulse Secure Desktop Client Version5.1 Updater6.0 SwPlatformmacos
PulsesecurePulse Secure Desktop Client Version5.1 Updater7.0 SwPlatformmacos
PulsesecurePulse Secure Desktop Client Version5.1 Updater8.0 SwPlatformmacos
PulsesecurePulse Secure Desktop Client Version5.1 Updater9.0 SwPlatformmacos
PulsesecurePulse Secure Desktop Client Version5.1 Updater9.1 SwPlatformmacos
PulsesecurePulse Secure Desktop Client Version5.1r Update3.2 SwPlatformmacos
PulsesecurePulse Secure Desktop Client Version5.1r Update5.0 SwPlatformmacos
PulsesecurePulse Secure Desktop Client Version5.3 Updater1 SwPlatformmacos
PulsesecurePulse Secure Desktop Client Version5.3 Updater1.1 SwPlatformmacos
PulsesecurePulse Secure Desktop Client Version5.3 Updater2 SwPlatformmacos
PulsesecurePulse Secure Desktop Client Version5.3 Updater3 SwPlatformmacos
PulsesecurePulse Secure Desktop Client Version5.3 Updater4 SwPlatformmacos
PulsesecurePulse Secure Desktop Client Version5.3 Updater4.1 SwPlatformmacos
PulsesecurePulse Secure Desktop Client Version5.3 Updater4.2 SwPlatformmacos
PulsesecurePulse Secure Desktop Client Version5.3 Updater5 SwPlatformmacos
PulsesecurePulse Secure Desktop Client Version5.3 Updater5.2 SwPlatformmacos
PulsesecurePulse Secure Desktop Client Version5.3 Updater6 SwPlatformmacos
PulsesecurePulse Secure Desktop Client Version5.3 Updater7 SwPlatformmacos
PulsesecurePulse Secure Desktop Client Version9.0 Updater1 SwPlatformmacos
PulsesecurePulse Secure Desktop Client Version9.0 Updater2 SwPlatformmacos
PulsesecurePulse Secure Desktop Client Version9.0 Updater2.1 SwPlatformmacos
PulsesecurePulse Secure Desktop Client Version9.0 Updater3 SwPlatformmacos
PulsesecurePulse Secure Desktop Client Version9.0 Updater3.2 SwPlatformmacos
PulsesecurePulse Secure Desktop Client Version9.0 Updater4 SwPlatformmacos
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.32% 0.522
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.