Medium severity6.5NVD Advisory· Published Jan 31, 2018· Updated Jun 17, 2026
CVE-2018-6374
CVE-2018-6374
Description
The GUI component (aka PulseUI) in Pulse Secure Desktop Linux clients before PULSE5.2R9.2 and 5.3.x before PULSE5.3R4.2 does not perform strict SSL Certificate Validation. This can lead to the manipulation of the Pulse Connection set.
Affected products
2- cpe:2.3:a:pulsesecure:desktop_linux_client:*:*:*:*:*:*:*:*Range: <5.2r9.2
- Range: <5.2R9.2, <5.3R4.2
Patches
Vulnerability mechanics
References
2- kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA43620nvdVendor Advisory
- www.securityfocus.com/bid/102908nvdThird Party AdvisoryVDB Entry
News mentions
0No linked articles in our index yet.