CVE-2018-6374

The GUI component (aka PulseUI) in Pulse Secure Desktop Linux clients before PULSE5.2R9.2 and 5.3.x before PULSE5.3R4.2 does not perform strict SSL Certificate Validation. This can lead to the manipulation of the Pulse Connection set.
References
Configurations

Configuration 1

cpe:2.3:a:pulsesecure:desktop_linux_client:*:*:*:*:*:*:*:*
cpe:2.3:a:pulsesecure:desktop_linux_client:*:*:*:*:*:*:*:*

Information

Published : 2018-01-31 09:29

Updated : 2018-02-24 09:37


NVD link : CVE-2018-6374

Mitre link : CVE-2018-6374

Products Affected
No products.
CWE
CWE-295

Improper Certificate Validation