« Volver al listado

CVE-2018-11002

Estado: ModificadaMedia (5.5)—

Pulse Secure Desktop Client 5.3 up to and including R6.0 build 1769 on Windows has Insecure Permissions.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2018-11002",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5.8,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 4.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 5.5,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2018-11-29T16:29:00.277",
  "references": [
    {
      "url": "http://www.securityfocus.com/bid/106054",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://www.themissinglink.com.au/security-advisories-cve-2017-16878-0",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/106054",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.themissinglink.com.au/security-advisories-cve-2017-16878-0",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-732"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Pulse Secure Desktop Client 5.3 up to and including R6.0 build 1769 on Windows has Insecure Permissions."
    },
    {
      "lang": "es",
      "value": "Pulse Secure Desktop Client desde la versión 5.3 hasta la R6.0 build 1769 en Windows tiene permisos no seguros."
    }
  ],
  "lastModified": "2026-06-17T01:35:04.753",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:pulsesecure:pulse_secure_desktop_client:5.3r1:*:*:*:*:windows:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CEFC320A-C766-4CDB-821F-38E7BCD29A92"
            },
            {
              "criteria": "cpe:2.3:a:pulsesecure:pulse_secure_desktop_client:5.3r1.1:*:*:*:*:windows:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2FFEC469-631A-46CB-A8E1-D40EAD13723A"
            },
            {
              "criteria": "cpe:2.3:a:pulsesecure:pulse_secure_desktop_client:5.3r2:*:*:*:*:windows:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E35C87D3-AA3F-458E-917C-9A26A207150A"
            },
            {
              "criteria": "cpe:2.3:a:pulsesecure:pulse_secure_desktop_client:5.3r3:*:*:*:*:windows:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F2413F85-C9AD-4DB1-967F-D9F32EFE278E"
            },
            {
              "criteria": "cpe:2.3:a:pulsesecure:pulse_secure_desktop_client:5.3r4:*:*:*:*:windows:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7E5335AC-D908-42C1-94EE-5DD99DE1E26B"
            },
            {
              "criteria": "cpe:2.3:a:pulsesecure:pulse_secure_desktop_client:5.3r4.1:*:*:*:*:windows:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B2CD2EEC-8CFB-48C1-9412-9DFA7692466E"
            },
            {
              "criteria": "cpe:2.3:a:pulsesecure:pulse_secure_desktop_client:5.3r4.2:*:*:*:*:windows:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DAADB2AC-95A0-43F3-B966-AC57FFEE203D"
            },
            {
              "criteria": "cpe:2.3:a:pulsesecure:pulse_secure_desktop_client:5.3r5:*:*:*:*:windows:*:*",
              "vulnerable": true,
              "matchCriteriaId": "423D3FE6-ACB4-43AC-8B05-624DE78CF4FB"
            },
            {
              "criteria": "cpe:2.3:a:pulsesecure:pulse_secure_desktop_client:5.3r5.2:*:*:*:*:windows:*:*",
              "vulnerable": true,
              "matchCriteriaId": "13CEC426-F457-4084-B788-688719DBF1C2"
            },
            {
              "criteria": "cpe:2.3:a:pulsesecure:pulse_secure_desktop_client:5.3r6:*:*:*:*:windows:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EEAD2760-513D-475B-9F1E-4C4CB1484D6F"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}