Back to Database
Status published
Medium
CVE-2018-14366
download.cgi in Pulse Secure Pulse Connect Secure 8.1RX before 8.1R13...
Vulnerability Description
download.cgi in Pulse Secure Pulse Connect Secure 8.1RX before 8.1R13 and 8.3RX before 8.3R4 and Pulse Policy Secure through 5.2RX before 5.2R10 and 5.4RX before 5.4R4 have an Open Redirect Vulnerability.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2018-14366
Credits & Attribution
No credits recorded in the NVD database.
More from ivanti
View All →CVE-2022-27088
Ivanti DSM Remote <= 6.3.1.1862 is vulnerable to an unquoted...
High
7.8
CVE-2021-44720
In Ivanti Pulse Secure Pulse Connect Secure (PCS) before 9.1R12,...
High
7.2
CVE-2021-38560
Ivanti Service Manager 2021.1 allows reflected XSS via the appName...
Medium
6.1
CVE-2021-36235
An issue was discovered in Ivanti Workspace Control before 10.6.30.0....
High
7.8
CVE-2021-30497
Ivanti Avalanche (Premise) 6.3.2 allows remote unauthenticated users to read...
High
7.5
Affected Vendor
ivanti
View all reports →Affected Software
connect secure, pulse connect secure, pulse policy secure
Vulnerable Versions:
8.1, 8.3, 8.1r1.0, 8.1rx, 8.3rx, 5.2r1.0, 5.2r2.0, 5.2r3.0, 5.2r3.2, 5.2r4.0, 5.2r5.0, 5.2r6.0, 5.2r7.0, 5.2r7.1, 5.2r8.0, 5.2r9.0, 5.2r9.1, 5.2rx, 5.4r1, 5.4r2, 5.4r2.1, 5.4r3, 5.4rx
Timeline
Official Publish:
September 6th, 2018
Last Modified:
August 5th, 2024
Added to House:
July 20th, 2026
CVSS Vectors
V3:
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.