imPC@ndo IT

Tracker / CVE-2014-3812

CVE-2014-3812

Medium 5.0

The Juniper Junos Pulse Secure Access Service (SSL VPN) devices with IVE OS before 7.4r5 and 8.x before 8.0r1 and Junos Pulse Access Control Service (UAC) before 4.4r5 and 5.x before 5.0r1 enable cipher suites with weak encryption algorithms, which make it easier for remote attackers to obtain sensitive information by sniffing the network.

Affected products and versions

juniper fips_infranet_controller_6500
juniper fips_secure_access_4000
juniper fips_secure_access_4500
juniper fips_secure_access_6000
juniper fips_secure_access_6500
juniper infranet_controller_4000
juniper infranet_controller_4500
juniper infranet_controller_6000
juniper infranet_controller_6500
juniper ive_os
juniper mag2600_gateway
juniper mag4610_gateway
juniper mag6610_gateway
juniper mag6611_gateway
juniper secure_access_2500
juniper secure_access_4500
juniper secure_access_700
juniper unified_access_control_software

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References