Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2014-3823


The Juniper Junos Pulse Secure Access Service (SSL VPN) devices with IVE OS 8.0 before 8.0r1, 7.4 before 7.4r5, and 7.1 before 7.1r18 allows remote attackers to conduct clickjacking attacks via unspecified vectors.


Published

2014-09-29T14:55:08.767

Last Modified

2025-04-12T10:46:40.837

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 4.3 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:N/I:P/A:N

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

8.6

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-20

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application juniper junos_pulse_secure_access_service 7.1 Yes
Application juniper junos_pulse_secure_access_service 7.1r1.1 Yes
Application juniper junos_pulse_secure_access_service 7.1r2 Yes
Application juniper junos_pulse_secure_access_service 7.1r3 Yes
Application juniper junos_pulse_secure_access_service 7.1r4 Yes
Application juniper junos_pulse_secure_access_service 7.1r5 Yes
Application juniper junos_pulse_secure_access_service 7.1r6 Yes
Application juniper junos_pulse_secure_access_service 7.1r7 Yes
Application juniper junos_pulse_secure_access_service 7.1r8 Yes
Application juniper junos_pulse_secure_access_service 7.1r9 Yes
Application juniper junos_pulse_secure_access_service 7.1r10 Yes
Application juniper junos_pulse_secure_access_service 7.1r11 Yes
Application juniper junos_pulse_secure_access_service 7.1r12 Yes
Application juniper junos_pulse_secure_access_service 7.1r13 Yes
Application juniper junos_pulse_secure_access_service 7.1r14 Yes
Application juniper junos_pulse_secure_access_service 7.1r15 Yes
Application juniper junos_pulse_secure_access_service 7.4 Yes
Application juniper junos_pulse_secure_access_service 7.4 Yes
Application juniper junos_pulse_secure_access_service 7.4 Yes
Application juniper junos_pulse_secure_access_service 7.4 Yes
Application juniper junos_pulse_secure_access_service 8.0 Yes

References