CVE-2014-3812
published 2014-06-13CVE-2014-3812: The Juniper Junos Pulse Secure Access Service (SSL VPN) devices with IVE OS before 7.4r5 and 8.x before 8.0r1 and Junos Pulse Access Control Service (UAC)…
PriorityP422medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
0.74%
50.5th percentile
The Juniper Junos Pulse Secure Access Service (SSL VPN) devices with IVE OS before 7.4r5 and 8.x before 8.0r1 and Junos Pulse Access Control Service (UAC) before 4.4r5 and 5.x before 5.0r1 enable cipher suites with weak encryption algorithms, which make it easier for remote attackers to obtain sensitive information by sniffing the network.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| juniper | ive_os | — | — |
| juniper | ive_os | — | — |
| juniper | junos_os | — | — |
| juniper | unified_access_control_software | — | — |
| juniper | unified_access_control_software | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ivanti
Ivanti Security Advisory: CVE-2014-3812
vendor_ivanti·2014-06-13
CVE-2014-3812 CWE-310 Ivanti Security Advisory: CVE-2014-3812
Ivanti Security Advisory: CVE-2014-3812
The Juniper Junos Pulse Secure Access Service (SSL VPN) devices with IVE OS before 7.4r5 and 8.x before 8.0r1 and Junos Pulse Access Control Service (UAC) before 4.4r5 and 5.x before 5.0r1 enable cipher suites with weak encryption algorithms, which make it easier for remote attackers to obtain sensitive information by sniffing the network.
CVE IDs: CVE-2014-3812
CWEs: CWE-310
Juniper
CVE-2014-3812: The Juniper Junos Pulse Secure Access Service (SSL VPN) devices with IVE OS before 7.4r5 and 8.x before 8.0r1 and Junos Pulse Access Control Service (
vendor_juniper·2014-06-13·CVSS 5.0
CVE-2014-3812 [MEDIUM] CWE-310 CVE-2014-3812: The Juniper Junos Pulse Secure Access Service (SSL VPN) devices with IVE OS before 7.4r5 and 8.x before 8.0r1 and Junos Pulse Access Control Service (
CVE-2014-3812: The Juniper Junos Pulse Secure Access Service (SSL VPN) devices with IVE OS before 7.4r5 and 8.x before 8.0r1 and Junos Pulse Access Control Service (UAC) before 4.4r5 and 5.x before 5.0r1 enable cipher suites with weak encryption algorithms, which make it easier for remote attackers to obtain sensitive information by sniffing the network.
GHSA
GHSA-j6f4-5ggj-5x99: The Juniper Junos Pulse Secure Access Service (SSL VPN) devices with IVE OS before 7
ghsa_unreviewed·2022-05-17
CVE-2014-3812 [MEDIUM] GHSA-j6f4-5ggj-5x99: The Juniper Junos Pulse Secure Access Service (SSL VPN) devices with IVE OS before 7
The Juniper Junos Pulse Secure Access Service (SSL VPN) devices with IVE OS before 7.4r5 and 8.x before 8.0r1 and Junos Pulse Access Control Service (UAC) before 4.4r5 and 5.x before 5.0r1 enable cipher suites with weak encryption algorithms, which make it easier for remote attackers to obtain sensitive information by sniffing the network.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2014-06-13
Published