Lucene search

K
cve[email protected]CVE-2014-3812
HistoryJun 13, 2014 - 2:55 p.m.

CVE-2014-3812

2014-06-1314:55:16
CWE-310
web.nvd.nist.gov
23
juniper
junos pulse
ssl vpn
ive os
access control service
uac
cve-2014-3812
vulnerability
weak encryption
network security
information security

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

6.4 Medium

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

56.5%

The Juniper Junos Pulse Secure Access Service (SSL VPN) devices with IVE OS before 7.4r5 and 8.x before 8.0r1 and Junos Pulse Access Control Service (UAC) before 4.4r5 and 5.x before 5.0r1 enable cipher suites with weak encryption algorithms, which make it easier for remote attackers to obtain sensitive information by sniffing the network.

Affected configurations

NVD
Node
juniperive_osMatch7.4
OR
juniperive_osMatch8.0
OR
juniperunified_access_control_softwareMatch4.4
OR
juniperunified_access_control_softwareMatch5.0
AND
juniperfips_infranet_controller_6500Match-
OR
juniperfips_secure_access_4000Match-
OR
juniperfips_secure_access_4500Match-
OR
juniperfips_secure_access_6000Match-
OR
juniperfips_secure_access_6500Match-
OR
juniperinfranet_controller_4000Match-
OR
juniperinfranet_controller_4500Match-
OR
juniperinfranet_controller_6000Match-
OR
juniperinfranet_controller_6500Match-
OR
junipermag2600_gatewayMatch-
OR
junipermag4610_gatewayMatch-
OR
junipermag6610_gatewayMatch-
OR
junipermag6611_gatewayMatch-
OR
junipersecure_access_2500Match-
OR
junipersecure_access_4500Match-
OR
junipersecure_access_700Match-

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

6.4 Medium

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

56.5%

Related for CVE-2014-3812