Lucene search

K
cvelistMitreCVELIST:CVE-2013-3970
HistoryOct 03, 2022 - 4:14 p.m.

CVE-2013-3970

2022-10-0316:14:45
mitre
www.cve.org
cve-2013-3970
juniper junos pulse
ssl vpn
ive os
uac
certification authority
man-in-the-middle

6.3 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

20.6%

Juniper Junos Pulse Secure Access Service (aka SSL VPN) with IVE OS 7.0r2 through 7.0r8 and 7.1r1 through 7.1r5 and Junos Pulse Access Control Service (aka UAC) with UAC OS 4.1r1 through 4.1r5 include a test Certification Authority (CA) certificate in the Trusted Server CAs list, which makes it easier for man-in-the-middle attackers to spoof SSL servers by leveraging control over that test CA.

6.3 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

20.6%

Related for CVELIST:CVE-2013-3970