CVE-2018-20809

EUVD-2018-13351
A crafted message can cause the web server to crash with Pulse Secure Pulse Connect Secure (PCS) 8.3RX before 8.3R5 and Pulse Policy Secure 5.4RX before 5.4R5. This is not applicable to PCS 8.1RX.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 87%
Affected Products (NVD)
VendorProductVersion
ivanticonnect_secure
8.3:r1
ivanticonnect_secure
8.3:r2
ivanticonnect_secure
8.3:r2.1
ivanticonnect_secure
8.3:r3
ivanticonnect_secure
8.3:r4
pulsesecurepulse_policy_secure
4.4:r1.0
pulsesecurepulse_policy_secure
4.4:r1.1
pulsesecurepulse_policy_secure
4.4:r10
pulsesecurepulse_policy_secure
4.4:r11.1
pulsesecurepulse_policy_secure
4.4:r12.0
pulsesecurepulse_policy_secure
4.4:r13.1
pulsesecurepulse_policy_secure
4.4:r13.2
pulsesecurepulse_policy_secure
4.4:r13.3
pulsesecurepulse_policy_secure
4.4:r130
pulsesecurepulse_policy_secure
4.4:r2.0
pulsesecurepulse_policy_secure
4.4:r3.0
pulsesecurepulse_policy_secure
4.4:r4.0
pulsesecurepulse_policy_secure
4.4:r5.0
pulsesecurepulse_policy_secure
4.4:r6.0
pulsesecurepulse_policy_secure
4.4:r7.0
pulsesecurepulse_policy_secure
4.4:r8.0
pulsesecurepulse_policy_secure
5.0:r1.0
pulsesecurepulse_policy_secure
5.0:r10.0
pulsesecurepulse_policy_secure
5.0:r11.0
pulsesecurepulse_policy_secure
5.0:r12.1
pulsesecurepulse_policy_secure
5.0:r13.0
pulsesecurepulse_policy_secure
5.0:r13.1
pulsesecurepulse_policy_secure
5.0:r2.0
pulsesecurepulse_policy_secure
5.0:r3.0
pulsesecurepulse_policy_secure
5.0:r3.2
pulsesecurepulse_policy_secure
5.0:r4.0
pulsesecurepulse_policy_secure
5.0:r4.1
pulsesecurepulse_policy_secure
5.0:r5.0
pulsesecurepulse_policy_secure
5.0:r6.0
pulsesecurepulse_policy_secure
5.0:r7.0
pulsesecurepulse_policy_secure
5.0:r7.1
pulsesecurepulse_policy_secure
5.0:r8.0
pulsesecurepulse_policy_secure
5.0:r8.1
pulsesecurepulse_policy_secure
5.0:r9.0
pulsesecurepulse_policy_secure
5.1:r1.0
pulsesecurepulse_policy_secure
5.1:r1.1
pulsesecurepulse_policy_secure
5.1:r10.0
pulsesecurepulse_policy_secure
5.1:r11.0
pulsesecurepulse_policy_secure
5.1:r12.0
pulsesecurepulse_policy_secure
5.1:r12.1
pulsesecurepulse_policy_secure
5.1:r13.0
pulsesecurepulse_policy_secure
5.1:r14.0
pulsesecurepulse_policy_secure
5.1:r2.0
pulsesecurepulse_policy_secure
5.1:r2.1
pulsesecurepulse_policy_secure
5.1:r3.0
pulsesecurepulse_policy_secure
5.1:r3.2
pulsesecurepulse_policy_secure
5.1:r4.0
pulsesecurepulse_policy_secure
5.1:r5.0
pulsesecurepulse_policy_secure
5.1:r6.0
pulsesecurepulse_policy_secure
5.1:r7.0
pulsesecurepulse_policy_secure
5.1:r8.0
pulsesecurepulse_policy_secure
5.1:r9.0
pulsesecurepulse_policy_secure
5.1:r9.1
pulsesecurepulse_policy_secure
5.2:r1.0
pulsesecurepulse_policy_secure
5.2:r10.0
pulsesecurepulse_policy_secure
5.2:r11.0
pulsesecurepulse_policy_secure
5.2:r2.0
pulsesecurepulse_policy_secure
5.2:r3.0
pulsesecurepulse_policy_secure
5.2:r3.2
pulsesecurepulse_policy_secure
5.2:r4.0
pulsesecurepulse_policy_secure
5.2:r5.0
pulsesecurepulse_policy_secure
5.2:r6.0
pulsesecurepulse_policy_secure
5.2:r7.0
pulsesecurepulse_policy_secure
5.2:r7.1
pulsesecurepulse_policy_secure
5.2:r8.0
pulsesecurepulse_policy_secure
5.2:r9.0
pulsesecurepulse_policy_secure
5.2:r9.1
pulsesecurepulse_policy_secure
5.3:r1.0
pulsesecurepulse_policy_secure
5.3:r1.1
pulsesecurepulse_policy_secure
5.3:r10.0
pulsesecurepulse_policy_secure
5.3:r11.0
pulsesecurepulse_policy_secure
5.3:r12.0
pulsesecurepulse_policy_secure
5.3:r2.0
pulsesecurepulse_policy_secure
5.3:r3.0
pulsesecurepulse_policy_secure
5.3:r3.1
pulsesecurepulse_policy_secure
5.3:r4.0
pulsesecurepulse_policy_secure
5.3:r4.1
pulsesecurepulse_policy_secure
5.3:r5.0
pulsesecurepulse_policy_secure
5.3:r5.1
pulsesecurepulse_policy_secure
5.3:r5.2
pulsesecurepulse_policy_secure
5.3:r6.0
pulsesecurepulse_policy_secure
5.3:r7.0
pulsesecurepulse_policy_secure
5.3:r8.0
pulsesecurepulse_policy_secure
5.3:r8.1
pulsesecurepulse_policy_secure
5.3:r8.2
pulsesecurepulse_policy_secure
5.3:r9.0
pulsesecurepulse_policy_secure
5.4:r1
pulsesecurepulse_policy_secure
5.4:r2
pulsesecurepulse_policy_secure
5.4:r2.1
pulsesecurepulse_policy_secure
5.4:r3
pulsesecurepulse_policy_secure
5.4:r4
𝑥
= Vulnerable software versions