| Vulnerability Name: | CVE-2014-2292 (CCN-94024) | ||||||||
| Assigned: | 2014-03-12 | ||||||||
| Published: | 2014-03-12 | ||||||||
| Updated: | 2014-03-17 | ||||||||
| Summary: | Unspecified vulnerability in the Linux Network Connect client in Juniper Junos Pulse Secure Access Service (aka SSL VPN) with IVE OS before 7.1r18, 7.3 before 7.3r10, 7.4 before 7.4r8, and 8.0 before 8.0r1 allows local users to gain privileges via unspecified vectors. | ||||||||
| CVSS v3 Severity: | 7.5 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H)
| ||||||||
| CVSS v2 Severity: | 7.2 High (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C) 5.3 Medium (Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
4.9 Medium (CCN Temporal CVSS v2 Vector: AV:L/AC:M/Au:S/C:C/I:C/A:C/E:U/RL:OF/RC:C)
| ||||||||
| Vulnerability Type: | CWE-noinfo | ||||||||
| Vulnerability Consequences: | Gain Privileges | ||||||||
| References: | Source: MITRE Type: CNA CVE-2014-2292 Source: CCN Type: BID-66379 Juniper Junos Pulse Secure Access CVE-2014-2292 Local Privilege Escalation Vulnerability Source: XF Type: UNKNOWN juniper-junos-cve20142292-priv-esc(94024) Source: CCN Type: Juniper Networks Security Bulletin JSA10616 Junos Pulse Secure Access Service (SSL VPN): Linux Network Connect client local user privilege escalation issue (CVE-2014-2292) Source: CONFIRM Type: Vendor Advisory https://kb.juniper.net/InfoCenter/index?page=content&id=JSA10616 | ||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
| BACK | |||||||||