HIGH · 7.8

CVE-2016-2408

Pulse Secure Desktop before 5.2R2 and Pulse Secure Installer Service before 8.2R2 and below for Windows allow restricted users to gain privileges via unspecified vectors.

Vulnerability Description

Pulse Secure Desktop before 5.2R2 and Pulse Secure Installer Service before 8.2R2 and below for Windows allow restricted users to gain privileges via unspecified vectors.

CVSS Score

7.8

HIGH

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
PulsesecureOdyssey Access Client<= 5.6r16.0
PulsesecurePulse Secure Desktop5.0r1.0
PulsesecurePulse Secure Security8.0r1.0
PulsesecureStandalone Pulse Installer Service7.4r1.0
MicrosoftWindowsAll versions

Related Weaknesses (CWE)

References

FAQ

What is CVE-2016-2408?

CVE-2016-2408 is a vulnerability with a CVSS score of 7.8 (HIGH). Pulse Secure Desktop before 5.2R2 and Pulse Secure Installer Service before 8.2R2 and below for Windows allow restricted users to gain privileges via unspecified vectors.

How severe is CVE-2016-2408?

CVE-2016-2408 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2016-2408?

Check the references section above for vendor advisories and patch information. Affected products include: Pulsesecure Odyssey Access Client, Pulsesecure Pulse Secure Desktop, Pulsesecure Pulse Secure Security, Pulsesecure Standalone Pulse Installer Service, Microsoft Windows.