CVE-2018-20809

A crafted message can cause the web server to crash with Pulse Secure Pulse Connect Secure (PCS) 8.3RX before 8.3R5 and Pulse Policy Secure 5.4RX before 5.4R5. This is not applicable to PCS 8.1RX.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 86%
VendorProductVersion
ivanticonnect_secure
8.3:r1
ivanticonnect_secure
8.3:r2
ivanticonnect_secure
8.3:r2.1
ivanticonnect_secure
8.3:r3
ivanticonnect_secure
8.3:r4
pulsesecurepulse_policy_secure
4.4:r1.0
pulsesecurepulse_policy_secure
4.4:r1.1
pulsesecurepulse_policy_secure
4.4:r10
pulsesecurepulse_policy_secure
4.4:r11.1
pulsesecurepulse_policy_secure
4.4:r12.0
pulsesecurepulse_policy_secure
4.4:r13.1
pulsesecurepulse_policy_secure
4.4:r13.2
pulsesecurepulse_policy_secure
4.4:r13.3
pulsesecurepulse_policy_secure
4.4:r130
pulsesecurepulse_policy_secure
4.4:r2.0
pulsesecurepulse_policy_secure
4.4:r3.0
pulsesecurepulse_policy_secure
4.4:r4.0
pulsesecurepulse_policy_secure
4.4:r5.0
pulsesecurepulse_policy_secure
4.4:r6.0
pulsesecurepulse_policy_secure
4.4:r7.0
pulsesecurepulse_policy_secure
4.4:r8.0
pulsesecurepulse_policy_secure
5.0:r1.0
pulsesecurepulse_policy_secure
5.0:r10.0
pulsesecurepulse_policy_secure
5.0:r11.0
pulsesecurepulse_policy_secure
5.0:r12.1
pulsesecurepulse_policy_secure
5.0:r13.0
pulsesecurepulse_policy_secure
5.0:r13.1
pulsesecurepulse_policy_secure
5.0:r2.0
pulsesecurepulse_policy_secure
5.0:r3.0
pulsesecurepulse_policy_secure
5.0:r3.2
pulsesecurepulse_policy_secure
5.0:r4.0
pulsesecurepulse_policy_secure
5.0:r4.1
pulsesecurepulse_policy_secure
5.0:r5.0
pulsesecurepulse_policy_secure
5.0:r6.0
pulsesecurepulse_policy_secure
5.0:r7.0
pulsesecurepulse_policy_secure
5.0:r7.1
pulsesecurepulse_policy_secure
5.0:r8.0
pulsesecurepulse_policy_secure
5.0:r8.1
pulsesecurepulse_policy_secure
5.0:r9.0
pulsesecurepulse_policy_secure
5.1:r1.0
pulsesecurepulse_policy_secure
5.1:r1.1
pulsesecurepulse_policy_secure
5.1:r10.0
pulsesecurepulse_policy_secure
5.1:r11.0
pulsesecurepulse_policy_secure
5.1:r12.0
pulsesecurepulse_policy_secure
5.1:r12.1
pulsesecurepulse_policy_secure
5.1:r13.0
pulsesecurepulse_policy_secure
5.1:r14.0
pulsesecurepulse_policy_secure
5.1:r2.0
pulsesecurepulse_policy_secure
5.1:r2.1
pulsesecurepulse_policy_secure
5.1:r3.0
pulsesecurepulse_policy_secure
5.1:r3.2
pulsesecurepulse_policy_secure
5.1:r4.0
pulsesecurepulse_policy_secure
5.1:r5.0
pulsesecurepulse_policy_secure
5.1:r6.0
pulsesecurepulse_policy_secure
5.1:r7.0
pulsesecurepulse_policy_secure
5.1:r8.0
pulsesecurepulse_policy_secure
5.1:r9.0
pulsesecurepulse_policy_secure
5.1:r9.1
pulsesecurepulse_policy_secure
5.2:r1.0
pulsesecurepulse_policy_secure
5.2:r10.0
pulsesecurepulse_policy_secure
5.2:r11.0
pulsesecurepulse_policy_secure
5.2:r2.0
pulsesecurepulse_policy_secure
5.2:r3.0
pulsesecurepulse_policy_secure
5.2:r3.2
pulsesecurepulse_policy_secure
5.2:r4.0
pulsesecurepulse_policy_secure
5.2:r5.0
pulsesecurepulse_policy_secure
5.2:r6.0
pulsesecurepulse_policy_secure
5.2:r7.0
pulsesecurepulse_policy_secure
5.2:r7.1
pulsesecurepulse_policy_secure
5.2:r8.0
pulsesecurepulse_policy_secure
5.2:r9.0
pulsesecurepulse_policy_secure
5.2:r9.1
pulsesecurepulse_policy_secure
5.3:r1.0
pulsesecurepulse_policy_secure
5.3:r1.1
pulsesecurepulse_policy_secure
5.3:r10.0
pulsesecurepulse_policy_secure
5.3:r11.0
pulsesecurepulse_policy_secure
5.3:r12.0
pulsesecurepulse_policy_secure
5.3:r2.0
pulsesecurepulse_policy_secure
5.3:r3.0
pulsesecurepulse_policy_secure
5.3:r3.1
pulsesecurepulse_policy_secure
5.3:r4.0
pulsesecurepulse_policy_secure
5.3:r4.1
pulsesecurepulse_policy_secure
5.3:r5.0
pulsesecurepulse_policy_secure
5.3:r5.1
pulsesecurepulse_policy_secure
5.3:r5.2
pulsesecurepulse_policy_secure
5.3:r6.0
pulsesecurepulse_policy_secure
5.3:r7.0
pulsesecurepulse_policy_secure
5.3:r8.0
pulsesecurepulse_policy_secure
5.3:r8.1
pulsesecurepulse_policy_secure
5.3:r8.2
pulsesecurepulse_policy_secure
5.3:r9.0
pulsesecurepulse_policy_secure
5.4:r1
pulsesecurepulse_policy_secure
5.4:r2
pulsesecurepulse_policy_secure
5.4:r2.1
pulsesecurepulse_policy_secure
5.4:r3
pulsesecurepulse_policy_secure
5.4:r4
𝑥
= Vulnerable software versions