PT-2019-10251 · Pulse Secure · Pulse Secure Desktop
Published
2019-03-16
·
Updated
2020-05-11
·
CVE-2018-20812
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Pulse Secure Desktop versions 9.0R1 and below
Description:
The issue is related to information exposure where IPv6 DNS traffic is sent outside of the VPN tunnel when Traffic Enforcement is enabled. This problem is specific to dual-stack endpoints that support both IPv4 and IPv6.
Recommendations:
For Pulse Secure Desktop versions 9.0R1 and below, consider disabling Traffic Enforcement as a temporary workaround to prevent IPv6 DNS traffic from being sent outside the VPN tunnel until a fix is available.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pulse Secure Desktop