CVE-2013-3970

UnknownEPSS 0.49%

Last modified

CVE-2013-3970 is a vulnerability of currently unknown severity. Juniper Junos Pulse Secure Access Service (aka SSL VPN) with IVE OS 7.0r2 through 7.0r8 and 7.1r1 through 7.1r5 and Junos Pulse Access Control Service (aka UAC) with UAC OS 4.1r1 through 4.1r5 include a test Certification Authority (CA) certificate in the Trusted Server CAs list, which makes it easier for man-in-the-middle attackers to spoof SSL servers by leveraging control over that test CA.. EPSS estimates a 0.49% chance of exploitation in the next 30 days.

Description

Juniper Junos Pulse Secure Access Service (aka SSL VPN) with IVE OS 7.0r2 through 7.0r8 and 7.1r1 through 7.1r5 and Junos Pulse Access Control Service (aka UAC) with UAC OS 4.1r1 through 4.1r5 include a test Certification Authority (CA) certificate in the Trusted Server CAs list, which makes it easier for man-in-the-middle attackers to spoof SSL servers by leveraging control over that test CA.

Metrics

EPSS Probability
0.49%

38.2th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
JuniperJunos Pulse Secure Access Service7.0r2
JuniperJunos Pulse Secure Access Service7.0r3
JuniperJunos Pulse Secure Access Service7.0r4
JuniperJunos Pulse Secure Access Service7.0r5
JuniperJunos Pulse Secure Access Service7.0r5.1
JuniperJunos Pulse Secure Access Service7.0r6
JuniperJunos Pulse Secure Access Service7.0r7
JuniperJunos Pulse Secure Access Service7.0r8
JuniperJunos Pulse Secure Access Service7.1r1
JuniperJunos Pulse Secure Access Service7.1r1.1
JuniperJunos Pulse Secure Access Service7.1r2
JuniperJunos Pulse Secure Access Service7.1r3
JuniperJunos Pulse Secure Access Service7.1r4
JuniperJunos Pulse Secure Access Service7.1r5
JuniperJunos Pulse Access Control Service4.1r1
JuniperJunos Pulse Access Control Service4.1r1.1
JuniperJunos Pulse Access Control Service4.1r2
JuniperJunos Pulse Access Control Service4.1r3
JuniperJunos Pulse Access Control Service4.1r4
JuniperJunos Pulse Access Control Service4.1r5

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2013-3970?
Juniper Junos Pulse Secure Access Service (aka SSL VPN) with IVE OS 7.0r2 through 7.0r8 and 7.1r1 through 7.1r5 and Junos Pulse Access Control Service (aka UAC) with UAC OS 4.1r1 through 4.1r5 include a test Certification Authority (CA) certificate in the Trusted Server CAs list, which makes it easier for man-in-the-middle attackers to spoof SSL servers by leveraging control over that test CA.
How severe is CVE-2013-3970?
Severity scoring for CVE-2013-3970 is pending analysis. The EPSS model estimates a 0.49% probability of exploitation in the next 30 days.
How do I fix CVE-2013-3970?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2013-3970?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST