mirror of
https://github.com/fkie-cad/nvd-json-data-feeds.git
synced 2025-05-28 09:11:28 +00:00
137 lines
4.9 KiB
JSON
137 lines
4.9 KiB
JSON
{
|
|
"id": "CVE-2015-5369",
|
|
"sourceIdentifier": "cve@mitre.org",
|
|
"published": "2015-08-11T14:59:12.710",
|
|
"lastModified": "2015-08-11T18:25:50.707",
|
|
"vulnStatus": "Analyzed",
|
|
"descriptions": [
|
|
{
|
|
"lang": "en",
|
|
"value": "Pulse Connect Secure (aka PCS and formerly Juniper PCS) PSC6000, PCS6500, and MAG PSC360 8.1 before 8.1r5, 8.0 before 8.0r13, 7.4 before 7.4r13.5, and 7.1 before 7.1r22.2 and PPS 5.1 before 5.1R5 and 5.0 before 5.0R13, when Hardware Acceleration is enabled, does not properly validate the Finished TLS handshake message, which makes it easier for remote attackers to conduct man-in-the-middle attacks via a crafted Finished message."
|
|
},
|
|
{
|
|
"lang": "es",
|
|
"value": "Vulnerabilidad en Pulse Connect Secure (tambi\u00e9n conocido como PCS y anteriormente Juniper PCS) PSC6000, PCS6500 y MAG PSC360 8.1 en versiones anteriores a 8.1r5, 8.0 en versiones anteriores a 8.0r13, 7.4 en versiones anteriores a 7.4r13.5, 7.1 en versiones anteriores a 7.1r22.2, PPS 5.1 en versiones anteriores a 5.1R5 y 5.0 en versiones anteriores a 5.0R13, cuando est\u00e1 habilitada Hardware Acceleration, no valida correctamente el mensaje del handshake de Finished TLS, lo que hace que sea m\u00e1s f\u00e1cil para los atacantes remotos realizar ataques man-in-the-middle a trav\u00e9s de un mensaje Finished manipulado."
|
|
}
|
|
],
|
|
"metrics": {
|
|
"cvssMetricV2": [
|
|
{
|
|
"source": "nvd@nist.gov",
|
|
"type": "Primary",
|
|
"cvssData": {
|
|
"version": "2.0",
|
|
"vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
|
|
"accessVector": "NETWORK",
|
|
"accessComplexity": "MEDIUM",
|
|
"authentication": "NONE",
|
|
"confidentialityImpact": "NONE",
|
|
"integrityImpact": "PARTIAL",
|
|
"availabilityImpact": "NONE",
|
|
"baseScore": 4.3
|
|
},
|
|
"baseSeverity": "MEDIUM",
|
|
"exploitabilityScore": 8.6,
|
|
"impactScore": 2.9,
|
|
"acInsufInfo": false,
|
|
"obtainAllPrivilege": false,
|
|
"obtainUserPrivilege": false,
|
|
"obtainOtherPrivilege": false,
|
|
"userInteractionRequired": false
|
|
}
|
|
]
|
|
},
|
|
"weaknesses": [
|
|
{
|
|
"source": "nvd@nist.gov",
|
|
"type": "Primary",
|
|
"description": [
|
|
{
|
|
"lang": "en",
|
|
"value": "CWE-17"
|
|
},
|
|
{
|
|
"lang": "en",
|
|
"value": "CWE-20"
|
|
}
|
|
]
|
|
}
|
|
],
|
|
"configurations": [
|
|
{
|
|
"operator": "AND",
|
|
"nodes": [
|
|
{
|
|
"operator": "OR",
|
|
"negate": false,
|
|
"cpeMatch": [
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:juniper:pulse_connect_secure:5.1:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "F03BD263-91F8-4AA7-882D-DC86F0896AFB"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:juniper:pulse_connect_secure:7.1:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "58B1967B-76D9-4E46-8E98-594684B53CC7"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:juniper:pulse_connect_secure:7.4:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "0C209D3C-C716-4A7F-9665-0C9C1DC2933F"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:juniper:pulse_connect_secure:8.0:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "BBDB9656-C040-4434-B484-31C682C55149"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:juniper:pulse_connect_secure:8.1:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "274B576D-5D83-4028-9732-0A394CA89FC3"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"operator": "OR",
|
|
"negate": false,
|
|
"cpeMatch": [
|
|
{
|
|
"vulnerable": false,
|
|
"criteria": "cpe:2.3:h:juniper:mag_pcs360:-:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "D7720B47-1EA4-4AD3-B3C3-CF99BD9A7B18"
|
|
},
|
|
{
|
|
"vulnerable": false,
|
|
"criteria": "cpe:2.3:h:juniper:pcs6000:-:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "7DD2AAF3-593E-439C-BFD9-E34309D05B4E"
|
|
},
|
|
{
|
|
"vulnerable": false,
|
|
"criteria": "cpe:2.3:h:juniper:pcs6500:-:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "8E50AEE1-08E6-43AE-9F4E-97BA1DECE72A"
|
|
}
|
|
]
|
|
}
|
|
]
|
|
}
|
|
],
|
|
"references": [
|
|
{
|
|
"url": "http://kb.juniper.net/InfoCenter/index?page=content&id=TSB16756",
|
|
"source": "cve@mitre.org"
|
|
},
|
|
{
|
|
"url": "http://www.securitytracker.com/id/1033166",
|
|
"source": "cve@mitre.org"
|
|
},
|
|
{
|
|
"url": "https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA40004",
|
|
"source": "cve@mitre.org"
|
|
},
|
|
{
|
|
"url": "https://vivaldi.net/en-US/blogs/entry/the-poodle-has-friends",
|
|
"source": "cve@mitre.org"
|
|
}
|
|
]
|
|
} |