The Vigil@nce team watches public vulnerabilities impacting your computers, and then offers security solutions, a database and tools to fix them.

Computer vulnerabilities of PulseSecure Connect Secure

computer vulnerability alert CVE-2015-7323

Pulse Connect Secure: access to a meeting via Secure Meeting

Synthesis of the vulnerability

An attacker can use Secure Meeting of Pulse Connect Secure, in order to obtain sensitive information.
Severity: 2/4.
Creation date: 28/09/2015.
Identifiers: CVE-2015-7323, SA40053, SA40054, VIGILANCE-VUL-17990.
Full Vigil@nce bulletin... (Free trial)

Description of the vulnerability

The Pulse Connect Secure product offers a Secure Meeting service.

However, an authenticated attacker can use the Java client (meetingAppSun.jar), to access to another meeting.

An attacker can therefore use Secure Meeting of Pulse Connect Secure, in order to obtain sensitive information.
Full Vigil@nce bulletin... (Free trial)

computer vulnerability announce CVE-2015-7322

Pulse Connect Secure: information disclosure via Secure Meeting

Synthesis of the vulnerability

An attacker can use a vulnerability in Secure Meeting of Pulse Connect Secure, in order to obtain sensitive information.
Severity: 2/4.
Creation date: 28/09/2015.
Identifiers: CVE-2015-7322, SA40053, SA40054, VIGILANCE-VUL-17989.
Full Vigil@nce bulletin... (Free trial)

Description of the vulnerability

The Pulse Connect Secure product offers a web service.

However, an attacker can bypass access restrictions to data, to enumerate meetings in progress of Secure Meeting (Pulse Collaboration).

An attacker can therefore use a vulnerability in Secure Meeting of Pulse Connect Secure, in order to obtain sensitive information.
Full Vigil@nce bulletin... (Free trial)

computer threat CVE-2015-5369

Pulse Secure Connect Secure: Man-in-the-Middle of Hardware Acceleration

Synthesis of the vulnerability

An attacker can perform a Man-in-the-Middle when the Hardware Acceleration is enabled on Pulse Secure Connect Secure, in order to read or alter TLS session data.
Severity: 2/4.
Creation date: 31/07/2015.
Identifiers: CVE-2015-5369, SA40004, TSB16756, VIGILANCE-VUL-17547.
Full Vigil@nce bulletin... (Free trial)

Description of the vulnerability

The Hardware Acceleration can be enabled on Pulse Secure Connect Secure.

However, in this case, it does not correctly compute the MAC of the TLS Handshake Finished Message. Using a second vulnerability, an attacker can thus perform a Man-in-the-Middle.

An attacker can therefore perform a Man-in-the-Middle when the Hardware Acceleration is enabled on Pulse Secure Connect Secure, in order to read or alter TLS session data.
Full Vigil@nce bulletin... (Free trial)

threat alert CVE-2015-1788 CVE-2015-1789 CVE-2015-1790

OpenSSL: four vulnerabilities

Synthesis of the vulnerability

An attacker can use several vulnerabilities of OpenSSL.
Severity: 2/4.
Number of vulnerabilities in this bulletin: 4.
Creation date: 12/06/2015.
Identifiers: 1450666, 1610582, 1647054, 1961111, 1961569, 1964113, 1964766, 1966038, 1970103, 1972125, 9010038, 9010039, BSA-2015-006, bulletinjul2015, c04760669, c05184351, c05353965, CERTFR-2015-AVI-257, CERTFR-2015-AVI-431, CERTFR-2016-AVI-128, CERTFR-2016-AVI-303, cisco-sa-20150612-openssl, cpuapr2017, cpuoct2017, CTX216642, CVE-2015-1788, CVE-2015-1789, CVE-2015-1790, CVE-2015-1792, DSA-3287-1, FEDORA-2015-10047, FEDORA-2015-10108, FreeBSD-SA-15:10.openssl, HPSBGN03678, HPSBHF03613, HPSBUX03388, JSA10694, JSA10733, NetBSD-SA2015-008, NTAP-20150616-0001, openSUSE-SU-2015:1139-1, openSUSE-SU-2015:1277-1, openSUSE-SU-2015:2243-1, openSUSE-SU-2016:0640-1, PAN-SA-2016-0020, PAN-SA-2016-0028, RHSA-2015:1115-01, RHSA-2015:1197-01, SA40002, SA98, SB10122, SOL16898, SOL16913, SOL16915, SOL16938, SSA:2015-162-01, SSRT102180, SUSE-SU-2015:1143-1, SUSE-SU-2015:1150-1, SUSE-SU-2015:1181-1, SUSE-SU-2015:1181-2, SUSE-SU-2015:1182-2, SUSE-SU-2015:1183-1, SUSE-SU-2015:1183-2, SUSE-SU-2015:1184-1, SUSE-SU-2015:1184-2, SUSE-SU-2015:1185-1, TNS-2015-07, TSB16728, USN-2639-1, VIGILANCE-VUL-17117.
Full Vigil@nce bulletin... (Free trial)

Description of the vulnerability

Several vulnerabilities were announced in OpenSSL.

An attacker can generate an infinite loop via ECParameters, in order to trigger a denial of service. [severity:2/4; CVE-2015-1788]

An attacker can force a read at an invalid address in X509_cmp_time(), in order to trigger a denial of service. [severity:2/4; CVE-2015-1789]

An attacker can force a NULL pointer to be dereferenced via EnvelopedContent, in order to trigger a denial of service. [severity:2/4; CVE-2015-1790]

An attacker can generate an infinite loop via CMS signedData, in order to trigger a denial of service. [severity:2/4; CVE-2015-1792]
Full Vigil@nce bulletin... (Free trial)

computer vulnerability note CVE-2015-1791

OpenSSL: use after free via NewSessionTicket

Synthesis of the vulnerability

An attacker, who own a malicious TLS server, can send the NewSessionTicket message, to force the usage of a freed memory area in a client linked to OpenSSL, in order to trigger a denial of service, and possibly to execute code.
Severity: 2/4.
Creation date: 04/06/2015.
Identifiers: 1961569, 1964113, 1970103, 2003480, 2003620, 2003673, 9010038, 9010039, bulletinjul2015, c04760669, c05184351, c05353965, CERTFR-2015-AVI-431, CERTFR-2016-AVI-128, CERTFR-2016-AVI-303, cisco-sa-20150612-openssl, cpuapr2017, cpuoct2016, cpuoct2017, CTX216642, CVE-2015-1791, DSA-3287-1, FEDORA-2015-10047, FEDORA-2015-10108, FreeBSD-SA-15:10.openssl, HPSBGN03678, HPSBHF03613, HPSBUX03388, JSA10694, JSA10733, NetBSD-SA2015-008, NTAP-20150616-0001, openSUSE-SU-2015:1139-1, openSUSE-SU-2016:0640-1, PAN-SA-2016-0020, PAN-SA-2016-0028, RHSA-2015:1115-01, SA40002, SA98, SB10122, SOL16914, SSA:2015-162-01, SSRT102180, SUSE-SU-2015:1143-1, SUSE-SU-2015:1150-1, SUSE-SU-2015:1182-2, SUSE-SU-2015:1184-1, SUSE-SU-2015:1184-2, SUSE-SU-2015:1185-1, TSB16728, USN-2639-1, VIGILANCE-VUL-17062.
Full Vigil@nce bulletin... (Free trial)

Description of the vulnerability

The TLS protocol uses the NewSessionTicket message to obtain a new session ticket (RFC 5077).

The ssl3_get_new_session_ticket() function of the ssl/s3_clnt.c file implements NewSessionTicket in an OpenSSL client. However, if the client is multi-threaded, this function frees a memory area before reusing it.

An attacker, who own a malicious TLS server, can therefore send the NewSessionTicket message, to force the usage of a freed memory area in a client linked to OpenSSL, in order to trigger a denial of service, and possibly to execute code.
Full Vigil@nce bulletin... (Free trial)

security note CVE-2015-4000

TLS: weakening Diffie-Hellman via Logjam

Synthesis of the vulnerability

An attacker, located as a Man-in-the-Middle, can force the TLS client/server to accept a weak export algorithm, in order to more easily capture or alter exchanged data.
Severity: 2/4.
Creation date: 20/05/2015.
Revision date: 20/05/2015.
Identifiers: 1610582, 1647054, 1957980, 1958984, 1959033, 1959539, 1959745, 1960194, 1960418, 1960862, 1962398, 1962694, 1963151, 9010038, 9010039, 9010041, 9010044, BSA-2015-005, bulletinjan2016, bulletinjul2015, c04725401, c04760669, c04767175, c04770140, c04773119, c04773241, c04774058, c04778650, c04832246, c04918839, c04926789, CERTFR-2016-AVI-303, CTX216642, CVE-2015-4000, DLA-507-1, DSA-3287-1, DSA-3300-1, DSA-3688-1, FEDORA-2015-10047, FEDORA-2015-10108, FEDORA-2015-9048, FEDORA-2015-9130, FEDORA-2015-9161, FreeBSD-EN-15:08.sendmail, FreeBSD-SA-15:10.openssl, HPSBGN03399, HPSBGN03407, HPSBGN03411, HPSBGN03417, HPSBHF03433, HPSBMU03345, HPSBMU03401, HPSBUX03363, HPSBUX03388, HPSBUX03435, HPSBUX03512, JSA10681, Logjam, NetBSD-SA2015-008, NTAP-20150616-0001, NTAP-20150715-0001, NTAP-20151028-0001, openSUSE-SU-2015:1139-1, openSUSE-SU-2015:1209-1, openSUSE-SU-2015:1216-1, openSUSE-SU-2015:1277-1, openSUSE-SU-2016:0226-1, openSUSE-SU-2016:0255-1, openSUSE-SU-2016:0261-1, openSUSE-SU-2016:2267-1, PAN-SA-2016-0020, PAN-SA-2016-0028, RHSA-2015:1072-01, RHSA-2015:1185-01, RHSA-2015:1197-01, RHSA-2016:2054-01, RHSA-2016:2055-01, RHSA-2016:2056-01, SA111, SA40002, SA98, SB10122, SSA:2015-219-02, SSRT102180, SSRT102254, SSRT102964, SSRT102977, SUSE-SU-2015:1143-1, SUSE-SU-2015:1150-1, SUSE-SU-2015:1177-1, SUSE-SU-2015:1177-2, SUSE-SU-2015:1181-1, SUSE-SU-2015:1181-2, SUSE-SU-2015:1182-2, SUSE-SU-2015:1183-1, SUSE-SU-2015:1183-2, SUSE-SU-2015:1184-1, SUSE-SU-2015:1184-2, SUSE-SU-2015:1185-1, SUSE-SU-2015:1268-1, SUSE-SU-2015:1268-2, SUSE-SU-2015:1269-1, SUSE-SU-2015:1581-1, SUSE-SU-2016:0224-1, SUSE-SU-2018:1768-1, TSB16728, USN-2624-1, USN-2625-1, USN-2656-1, USN-2656-2, VIGILANCE-VUL-16950, VN-2015-007.
Full Vigil@nce bulletin... (Free trial)

Description of the vulnerability

The Diffie-Hellman algorithm is used to exchange cryptographic keys. The DHE_EXPORT suite uses prime numbers smaller than 512 bits.

The Diffie-Hellman algorithm is used by TLS. However, during the negotiation, an attacker, located as a Man-in-the-Middle, can force TLS to use DHE_EXPORT (event if stronger suites are available).

This vulnerability can then be combined with VIGILANCE-VUL-16951.

An attacker, located as a Man-in-the-Middle, can therefore force the TLS client/server to accept a weak export algorithm, in order to more easily capture or alter exchanged data.
Full Vigil@nce bulletin... (Free trial)

vulnerability note CVE-2014-3823

Junos Pulse SSL VPN: clickjacking

Synthesis of the vulnerability

An attacker can trigger a clickjacking on Junos Pulse SSL VPN, in order to force the victim to perform unwanted operations.
Severity: 2/4.
Creation date: 10/09/2014.
Identifiers: CERTFR-2014-AVI-387, CVE-2014-3823, JSA10647, VIGILANCE-VUL-15332.
Full Vigil@nce bulletin... (Free trial)

Description of the vulnerability

The Junos Pulse SSL VPN product offers a web service.

However, it does not use the X-Frame-Options header which forbids to include pages in a frame of another site.

An attacker can therefore trigger a clickjacking on Junos Pulse SSL VPN, in order to force the victim to perform unwanted operations.
Full Vigil@nce bulletin... (Free trial)

security alert CVE-2007-5846

Net-SNMP: denial of service via GETBULK

Synthesis of the vulnerability

An attacker can create a denial of service by requesting numerous data with GETBULK.
Severity: 2/4.
Creation date: 08/11/2007.
Identifiers: 1712988, BID-26378, CVE-2007-5846, DSA-1483-1, FEDORA-2007-3019, MDKSA-2007:225, RHSA-2007:1045-01, SA43730, SUSE-SR:2007:025, VIGILANCE-VUL-7325, VMSA-2008-0007, VMSA-2008-0007.1, VMSA-2008-0007.2.
Full Vigil@nce bulletin... (Free trial)

Description of the vulnerability

The SNMP protocol defines several query types:
 - SET : change a parameter
 - GET : read a parameter
 - GETNEXT : obtain the next parameter
 - GETBULK : repeat GETNEXT, until a maximum indicated in the query

However, there is no limit on the number of repetitions of GETBULK. An attacker can therefore, with one request, force the SNMP server to obtain and transfer a lot of data.

An attacker can thus create a denial of service.
Full Vigil@nce bulletin... (Free trial)
Our database contains other pages. You can request a free trial to read them.

Display information about PulseSecure Connect Secure: