CVE-2018-20810: Weak Encryption
Session data between cluster nodes during cluster synchronization is not properly encrypted in Pulse Secure Pulse Connect Secure (PCS) 8.3RX before 8.3R2 and Pulse Policy Secure (PPS) 5.4RX before 5.4R2. This is not applicable to PCS 8.1RX, PPS 5.2RX, or stand-alone devices.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2018-20810.
What is the title of this vulnerability?
The title of this vulnerability is 'Session data between cluster nodes during cluster synchronization is not properly encrypted in Pulse Secure Pulse Connect Secure (PCS) 8.3RX before 8.3R2 and Pulse Policy Secure (PPS) 5.4RX before 5.4R2.'
What is the severity of CVE-2018-20810?
The severity of CVE-2018-20810 is critical with a severity value of 9.8.
Which software versions are affected by CVE-2018-20810?
Pulse Secure Pulse Connect Secure (PCS) 8.3RX before 8.3R2 and Pulse Policy Secure (PPS) 5.4RX before 5.4R2 are affected by CVE-2018-20810. It is not applicable to PCS 8.1RX, PPS 5.2RX, or stand-alone devices.
How can I fix CVE-2018-20810?
To fix CVE-2018-20810, update Pulse Secure Pulse Connect Secure (PCS) to version 8.3R2 or later and update Pulse Policy Secure (PPS) to version 5.4R2 or later.