CVE-2013-5650
Junos Pulse Secure Access Service (IVE) 7.1 before 7.1r5, 7.2 before 7.2r10, 7.3 before 7.3r6, and 7.4 before 7.4r3 and Junos Pulse Access Control Service (UAC) 4.1 before 4.1r8.1, 4.2 before 4.2r5, 4.3 before 4.3r6 and 4.4 before 4.4r3, when a hardware…
Does this matter?
Lower severity and a low EPSS score (1.83%). Track it; it rarely justifies an emergency change on its own.
Description
Junos Pulse Secure Access Service (IVE) 7.1 before 7.1r5, 7.2 before 7.2r10, 7.3 before 7.3r6, and 7.4 before 7.4r3 and Junos Pulse Access Control Service (UAC) 4.1 before 4.1r8.1, 4.2 before 4.2r5, 4.3 before 4.3r6 and 4.4 before 4.4r3, when a hardware SSL acceleration card is enabled, allows remote attackers to cause a denial of service (device hang) via a crafted packet.
- CVSS 2.0
- 5.4 MEDIUMAV:N/AC:H/Au:N/C:N/I:N/A:C
- EPSS
- 1.83% probability · 78th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- juniper/junos pulse secure access service · juniper/junos pulse access control service
- Source
- cve@mitre.org
References
- http://osvdb.org/97241
- http://secunia.com/advisories/54776Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/87063
- https://kb.juniper.net/InfoCenter/index?cmid=no&page=content&id=JSA10590Vendor Advisory
- http://osvdb.org/97241
- http://secunia.com/advisories/54776Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/87063
- https://kb.juniper.net/InfoCenter/index?cmid=no&page=content&id=JSA10590Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.