CVE-2018-20812
Last modified
CVE-2018-20812 is a vulnerability of currently unknown severity. An information exposure issue where IPv6 DNS traffic would be sent outside of the VPN tunnel (when Traffic Enforcement was enabled) exists in Pulse Secure Pulse Secure Desktop 9.0R1 and below. This is applicable only to dual-stack (IPv4/IPv6) endpoints.. EPSS estimates a 1.11% chance of exploitation in the next 30 days.
Description
An information exposure issue where IPv6 DNS traffic would be sent outside of the VPN tunnel (when Traffic Enforcement was enabled) exists in Pulse Secure Pulse Secure Desktop 9.0R1 and below. This is applicable only to dual-stack (IPv4/IPv6) endpoints.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Pulsesecure | Pulse Secure Desktop Client | 4.0 | R1.0 |
| Pulsesecure | Pulse Secure Desktop Client | 5.1 | R1.0 |
| Pulsesecure | Pulse Secure Desktop Client | 5.1r | 3.2 |
| Pulsesecure | Pulse Secure Desktop Client | 5.3 | R1 |
| Pulsesecure | Pulse Secure Desktop Client | 9.0 | R1 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-20812?
How severe is CVE-2018-20812?
How do I fix CVE-2018-20812?
Are you affected by CVE-2018-20812?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
