CVE-2014-2292: High severity Juniper IVE OS vulnerability
Unspecified vulnerability in the Linux Network Connect client in Juniper Junos Pulse Secure Access Service (aka SSL VPN) with IVE OS before 7.1r18, 7.3 before 7.3r10, 7.4 before 7.4r8, and 8.0 before 8.0r1 allows local users to gain privileges via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-2292?
CVE-2014-2292 has been classified with a severity that indicates local user privilege escalation risks in affected versions.
How do I fix CVE-2014-2292?
To fix CVE-2014-2292, update to Junos Pulse Secure Access Service versions 7.1r18, 7.3r10, 7.4r8, or 8.0r1 and later.
What versions are affected by CVE-2014-2292?
CVE-2014-2292 affects Juniper IVE OS versions prior to 7.1r18, 7.3r10, 7.4r8, and 8.0r1.
Can local users exploit CVE-2014-2292?
Yes, local users can exploit CVE-2014-2292 to gain elevated privileges on the affected systems.
Is there an official patch for CVE-2014-2292?
Yes, Juniper has released patches for CVE-2014-2292 in the specified updated versions.