VulnerabilityModified
CVE-2018-9849
Pulse Secure Pulse Connect Secure 8.1.x before 8.1R14, 8.2.x before 8.2R11, and 8.3.x before 8.3R5 do not properly process nested XML entities, which allows remote attackers to cause a denial of service (memory consumption and memory errors) via a…
MEDIUM 5.5EPSS 0.99%
Does this matter?
Lower severity and a low EPSS score (0.99%). Track it; it rarely justifies an emergency change on its own.
Description
Pulse Secure Pulse Connect Secure 8.1.x before 8.1R14, 8.2.x before 8.2R11, and 8.3.x before 8.3R5 do not properly process nested XML entities, which allows remote attackers to cause a denial of service (memory consumption and memory errors) via a crafted XML document.
- CVSS 3.0
- 5.5 MEDIUMCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
- EPSS
- 0.99% probability · 61th percentile
- CISA KEV
- Not listed
- Affected
- pulsesecure/pulse connect secure
- Source
- cve@mitre.org
References
- http://www.securityfocus.com/bid/104160Third Party Advisory, VDB Entry
- https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA43730Vendor Advisory
- http://www.securityfocus.com/bid/104160Third Party Advisory, VDB Entry
- https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA43730Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.