Vulnerability Description
An information exposure issue where IPv6 DNS traffic would be sent outside of the VPN tunnel (when Traffic Enforcement was enabled) exists in Pulse Secure Pulse Secure Desktop 9.0R1 and below. This is applicable only to dual-stack (IPv4/IPv6) endpoints.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Pulsesecure | Pulse Secure Desktop Client | 4.0 |
Related Weaknesses (CWE)
References
- https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA43877/Vendor Advisory
- https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA43877/Vendor Advisory
FAQ
What is CVE-2018-20812?
CVE-2018-20812 is a vulnerability with a CVSS score of 7.5 (HIGH). An information exposure issue where IPv6 DNS traffic would be sent outside of the VPN tunnel (when Traffic Enforcement was enabled) exists in Pulse Secure Pulse Secure Desktop 9.0R1 and below. This is...
How severe is CVE-2018-20812?
CVE-2018-20812 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-20812?
Check the references section above for vendor advisories and patch information. Affected products include: Pulsesecure Pulse Secure Desktop Client.