peter bassill · operator
$ cve CVE-2018-6320 JSON

CVE-2018-6320

9.8
CRITICAL · CVSS 3.0 · EPSS 4.1% (pctl 90)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

A vulnerability has been discovered in login.cgi in Pulse Secure Pulse Connect Secure (PCS) 8.1RX before 8.1R12 and 8.3RX before 8.3R2 and Pulse Policy Secure (PPS) 5.2RX before 5.2R9 and 5.4RX before 5.4R2 wherein an http(s) Host header received from the browser is trusted without validation.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS4.08% — more likely to be exploited than 90% of all CVEs
WeaknessCWE-20
On CISA KEVno
Public exploitnone known
Published2018-09-06
Last modified2026-06-17

Affected (3)

VendorProduct
ivanticonnect secure
pulsesecurepulse connect secure
pulsesecurepulse policy secure

References

→ the Explorer  ·  watch your stack  ·  NVD