CVE-2015-5369: Input Validation
Pulse Connect Secure (aka PCS and formerly Juniper PCS) PSC6000, PCS6500, and MAG PSC360 8.1 before 8.1r5, 8.0 before 8.0r13, 7.4 before 7.4r13.5, and 7.1 before 7.1r22.2 and PPS 5.1 before 5.1R5 and 5.0 before 5.0R13, when Hardware Acceleration is enabled, does not properly validate the Finished TLS handshake message, which makes it easier for remote attackers to conduct man-in-the-middle attacks via a crafted Finished message.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-5369?
CVE-2015-5369 has a high severity rating due to its potential to allow unauthorized access through improper validation.
How do I fix CVE-2015-5369?
To fix CVE-2015-5369, upgrade your Pulse Connect Secure to version 5.1R5, 8.1r5, 8.0r13, 7.4r13.5, or 7.1r22.2.
What products are impacted by CVE-2015-5369?
CVE-2015-5369 affects specific versions of Pulse Connect Secure including 5.1, 7.1, 7.4, 8.0, and 8.1.
What versions are safe from CVE-2015-5369?
Versions of Pulse Connect Secure released after the critical updates provided in response to CVE-2015-5369 are considered safe.
Is hardware acceleration related to CVE-2015-5369?
Yes, CVE-2015-5369 specifically occurs when Hardware Acceleration is enabled on the affected systems.