HIGH
An information exposure issue where IPv6 DNS traffic would be sent outside of the VPN tunnel (when Traffic Enforcement was enabled) exists in Pulse Secure Pulse Secure Desktop 9.0R1 and below
Published Mar 16, 2019
7.5
HIGHCVSS 3.0
EPSS 1.11%
Description
An information exposure issue where IPv6 DNS traffic would be sent outside of the VPN tunnel (when Traffic Enforcement was enabled) exists in Pulse Secure Pulse Secure Desktop 9.0R1 and below. This is applicable only to dual-stack (IPv4/IPv6) endpoints.
Affected products
No data.
OR
- 4.0
- 4.0
- 4.0
- 4.0
- 4.0
- 4.0
- 4.0
- 4.0
- 4.0
- 4.0
- 4.0
- 4.0
- 4.0
- 4.0
- 4.0
- 4.0
- 5.1
- 5.1
- 5.1
- 5.1
- 5.1
- 5.1
- 5.1
- 5.1
- 5.1
- 5.1
- 5.1
- 5.1
- 5.1
- 5.1
- 5.1
- 5.1
- 5.1
- 5.1
- 5.1r
- 5.1r
- 5.3
- 5.3
- 5.3
- 5.3
- 5.3
- 5.3
- 5.3
- 5.3
- 5.3
- 5.3
- 5.3
- 9.0
- 9.0
- 9.0
- 9.0
- 9.0
- 9.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (1)
- https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA43877/ x_refsource_CONFIRMVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA43877/ | x_refsource_CONFIRMVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Mar 16, 2019
Updated Sep 16, 2024
Reserved Mar 15, 2019
Link CVE-2018-20812
CISA Vulnrichment
Updated n/a