← Back

CVE-2015-5369

nvd nist
Published: Aug 11, 2015Modified: May 6, 2026

JSON object

Loading...
4.3
Vector
AV:N/AC:M/Au:N/C:N/I:P/A:N
Exploitability: 8.6 / Impact: 2.9
Source: NVD

Description

Pulse Connect Secure (aka PCS and formerly Juniper PCS) PSC6000, PCS6500, and MAG PSC360 8.1 before 8.1r5, 8.0 before 8.0r13, 7.4 before 7.4r13.5, and 7.1 before 7.1r22.2 and PPS 5.1 before 5.1R5 and 5.0 before 5.0R13, when Hardware Acceleration is enabled, does not properly validate the Finished TLS handshake message, which makes it easier for remote attackers to conduct man-in-the-middle attacks via a crafted Finished message.

Affected (5)

1 product
Pulse Connect Secure
Configuration A
5 vulnerable · 3 platform
Vulnerable SoftwareAffected Versions
Juniper
Version 5.1
Version 7.1
Version 7.4
Version 8.0
Version 8.1
Running on/withPlatform Versions
Juniper
Mag Pcs360
All versions
Juniper
Pcs6000
All versions
Juniper
Pcs6500
All versions

Timeline

No history available yet.