CVE-2018-16261

Severity CVSS v4.0:
Pending analysis
Type:
CWE-295 Improper Certificate Validation
Publication date:
06/09/2018
Last modified:
03/10/2019

Description

In Pulse Secure Pulse Desktop Client 5.3RX before 5.3R5 and 9.0R1, there is a Privilege Escalation Vulnerability with Dynamic Certificate Trust.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:pulsesecure:pulse_secure_desktop_client:5.3r1:*:*:*:*:windows:*:*
cpe:2.3:a:pulsesecure:pulse_secure_desktop_client:5.3r1.1:*:*:*:*:windows:*:*
cpe:2.3:a:pulsesecure:pulse_secure_desktop_client:5.3r2:*:*:*:*:windows:*:*
cpe:2.3:a:pulsesecure:pulse_secure_desktop_client:5.3r3:*:*:*:*:windows:*:*
cpe:2.3:a:pulsesecure:pulse_secure_desktop_client:5.3r4:*:*:*:*:windows:*:*
cpe:2.3:a:pulsesecure:pulse_secure_desktop_client:5.3r4.1:*:*:*:*:windows:*:*
cpe:2.3:a:pulsesecure:pulse_secure_desktop_client:5.3r4.2:*:*:*:*:windows:*:*
cpe:2.3:a:pulsesecure:pulse_secure_desktop_client:5.3rx:*:*:*:*:windows:*:*
cpe:2.3:a:pulsesecure:pulse_secure_desktop_client:9.0r1:*:*:*:*:windows:*:*