Unrated severityNVD Advisory· Published Sep 6, 2018· Updated Aug 5, 2024
CVE-2018-6320
CVE-2018-6320
Description
A vulnerability has been discovered in login.cgi in Pulse Secure Pulse Connect Secure (PCS) 8.1RX before 8.1R12 and 8.3RX before 8.3R2 and Pulse Policy Secure (PPS) 5.2RX before 5.2R9 and 5.4RX before 5.4R2 wherein an http(s) Host header received from the browser is trusted without validation.
Affected products
2- Range: 8.1RX < 8.1R12, 8.3RX < 8.3R2
- Range: 5.2RX < 5.2R9, 5.4RX < 5.4R2
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA43877mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.