CVE-2018-11002
UnknownEPSS 0.90%
Last modified
CVE-2018-11002 is a vulnerability of currently unknown severity. Pulse Secure Desktop Client 5.3 up to and including R6.0 build 1769 on Windows has Insecure Permissions.. EPSS estimates a 0.90% chance of exploitation in the next 30 days.
Description
Pulse Secure Desktop Client 5.3 up to and including R6.0 build 1769 on Windows has Insecure Permissions.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Pulsesecure | Pulse Secure Desktop Client | 5.3r1 |
| Pulsesecure | Pulse Secure Desktop Client | 5.3r1.1 |
| Pulsesecure | Pulse Secure Desktop Client | 5.3r2 |
| Pulsesecure | Pulse Secure Desktop Client | 5.3r3 |
| Pulsesecure | Pulse Secure Desktop Client | 5.3r4 |
| Pulsesecure | Pulse Secure Desktop Client | 5.3r4.1 |
| Pulsesecure | Pulse Secure Desktop Client | 5.3r4.2 |
| Pulsesecure | Pulse Secure Desktop Client | 5.3r5 |
| Pulsesecure | Pulse Secure Desktop Client | 5.3r5.2 |
| Pulsesecure | Pulse Secure Desktop Client | 5.3r6 |
References
- http://www.securityfocus.com/bid/106054Third Party Advisory, VDB Entry
- https://www.themissinglink.com.au/security-advisories-cve-2017-16878-0Exploit, Third Party Advisory
- http://www.securityfocus.com/bid/106054Third Party Advisory, VDB Entry
- https://www.themissinglink.com.au/security-advisories-cve-2017-16878-0Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-11002?
Pulse Secure Desktop Client 5.3 up to and including R6.0 build 1769 on Windows has Insecure Permissions.
How severe is CVE-2018-11002?
Severity scoring for CVE-2018-11002 is pending analysis. The EPSS model estimates a 0.90% probability of exploitation in the next 30 days.
How do I fix CVE-2018-11002?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-10995SchedMD Slurm before 17.02.11 and 17.1x.x before 17.11.7 mis…
- CVE-2018-10996The weblogin_log function in /htdocs/cgibin on D-Link DIR-62…
- CVE-2018-10997Etere EtereWeb before 28.1.20 has a pre-authentication blind…
- CVE-2018-10998An issue was discovered in Exiv2 0.26. readMetadata in jp2im…6.5
- CVE-2018-10999An issue was discovered in Exiv2 0.26. The Exiv2::Internal::…
- CVE-2018-1100zsh through version 5.4.2 is vulnerable to a stack-based buf…7.8
- CVE-2018-11003An issue was discovered in YXcms 1.4.7. Cross-site request f…
- CVE-2018-11004An issue was discovered in SDcms v1.5. Cross-site request fo…
- CVE-2018-11005A Memory Leak issue was discovered in K7Computing K7AntiViru…5.5
- CVE-2018-11006An Incorrect Access Control issue was discovered in K7Comput…5.5
- CVE-2018-11007A Memory Leak issue was discovered in K7Computing K7AntiViru…5.5
- CVE-2018-11008An Incorrect Access Control issue was discovered in K7Comput…5.5
Are you affected by CVE-2018-11002?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
