CVE-2013-3970

CWE-3104 documents4 sources
Severity
4.3MEDIUM
EPSS
0.2%
top 59.69%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 13
Latest updateMay 17

Description

Juniper Junos Pulse Secure Access Service (aka SSL VPN) with IVE OS 7.0r2 through 7.0r8 and 7.1r1 through 7.1r5 and Junos Pulse Access Control Service (aka UAC) with UAC OS 4.1r1 through 4.1r5 include a test Certification Authority (CA) certificate in the Trusted Server CAs list, which makes it easier for man-in-the-middle attackers to spoof SSL servers by leveraging control over that test CA.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages2 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-x2pg-v5fr-hp3f: Juniper Junos Pulse Secure Access Service (aka SSL VPN) with IVE OS 72022-05-17
CVEList
CVE-2013-3970: Juniper Junos Pulse Secure Access Service (aka SSL VPN) with IVE OS 72013-06-13

📋Vendor Advisories

1
Juniper
CVE-2013-3970: Juniper Junos Pulse Secure Access Service (aka SSL VPN) with IVE OS 7.0r2 through 7.0r8 and 7.1r1 through 7.1r5 and Junos Pulse Access Control Service2013-06-13