Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2015-5369

Опубликовано: 11 авг. 2015
Источник: nvd
CVSS2: 4.3
EPSS Низкий

Описание

Pulse Connect Secure (aka PCS and formerly Juniper PCS) PSC6000, PCS6500, and MAG PSC360 8.1 before 8.1r5, 8.0 before 8.0r13, 7.4 before 7.4r13.5, and 7.1 before 7.1r22.2 and PPS 5.1 before 5.1R5 and 5.0 before 5.0R13, when Hardware Acceleration is enabled, does not properly validate the Finished TLS handshake message, which makes it easier for remote attackers to conduct man-in-the-middle attacks via a crafted Finished message.

Уязвимые конфигурации

Конфигурация 1

Одновременно

Одно из

cpe:2.3:a:juniper:pulse_connect_secure:5.1:*:*:*:*:*:*:*
cpe:2.3:a:juniper:pulse_connect_secure:7.1:*:*:*:*:*:*:*
cpe:2.3:a:juniper:pulse_connect_secure:7.4:*:*:*:*:*:*:*
cpe:2.3:a:juniper:pulse_connect_secure:8.0:*:*:*:*:*:*:*
cpe:2.3:a:juniper:pulse_connect_secure:8.1:*:*:*:*:*:*:*

Одно из

cpe:2.3:h:juniper:mag_pcs360:-:*:*:*:*:*:*:*
cpe:2.3:h:juniper:pcs6000:-:*:*:*:*:*:*:*
cpe:2.3:h:juniper:pcs6500:-:*:*:*:*:*:*:*

EPSS

Процентиль: 59%
0.00377
Низкий

4.3 Medium

CVSS2

Дефекты

CWE-17

Связанные уязвимости

github
больше 3 лет назад

Pulse Connect Secure (aka PCS and formerly Juniper PCS) PSC6000, PCS6500, and MAG PSC360 8.1 before 8.1r5, 8.0 before 8.0r13, 7.4 before 7.4r13.5, and 7.1 before 7.1r22.2 and PPS 5.1 before 5.1R5 and 5.0 before 5.0R13, when Hardware Acceleration is enabled, does not properly validate the Finished TLS handshake message, which makes it easier for remote attackers to conduct man-in-the-middle attacks via a crafted Finished message.

EPSS

Процентиль: 59%
0.00377
Низкий

4.3 Medium

CVSS2

Дефекты

CWE-17