CVE-2018-14366Open Redirect in Ivanti Connect Secure

CWE-601Open Redirect3 documents3 sources
Severity
6.1MEDIUMNVD
EPSS
0.1%
top 72.30%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 6
Latest updateMay 13

Description

download.cgi in Pulse Secure Pulse Connect Secure 8.1RX before 8.1R13 and 8.3RX before 8.3R4 and Pulse Policy Secure through 5.2RX before 5.2R10 and 5.4RX before 5.4R4 have an Open Redirect Vulnerability.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages3 packages

NVDpulsesecure/pulse_connect_secure8.1r1.0, 8.1rx, 8.3rx+2
NVDivanti/connect_secure8.1, 8.3+1

🔴Vulnerability Details

2
GHSA
GHSA-8mgx-h5p4-xxxm: download2022-05-13
CVEList
CVE-2018-14366: download2018-09-06
CVE-2018-14366 — Open Redirect in Ivanti Connect Secure | cvebase