Juniper Ssl Vpn Appliance Vulnerability
The instance of pulse secure formerly juniper networks junos pulse pulse connect secure ssl vpn running on the remote host is affected by a path traversal vulnerability.
Juniper ssl vpn appliance vulnerability. A remote unauthenticated attacker can exploit this issue via a specially crafted http request to access arbitrary files on the remote host. Juniper networks sa2000 ssl vpn appliance welcome cgi cross site scripting edb id. Junos os is not affected by cve 2016 0701 cve 2016 0800 cve 2016 2107 cve 2016 2176 cve 2016 2179 cve 2016 2181 cve 2016 6308 cve 2016 6309 and cve 2016 7052. The juniper networks sa6500 ssl vpn appliance successfully provided a less than 1 percent failure rate across all the tests in the series.
For immediate assistance jtac is available 24 hours a day by calling 888 314 jtac free north america or 1 408 745 9500. Provided solution for nsm appliances and junos space. No juniper products are affected by this vulnerability. Juniper employees now have unified access to wired and wired networks which makes self service byod possible.
It had a 99 87 percent success rate for sustaining from 7 112 to 10 668 tunnels for a period of two plus hours. Junos os is potentially affected by many of these issues. Cve 2016 2176 is a vulnerability that only affects ebcdic systems. Updated the status of ssl vpn products as vulnerable to lesser security risks updated the list of known cves related to shellshock issue.
Data sheet for juniper networks secure access ssl vpn appliance sa 6000 starting price. Unified access control leverages pulse secure s mag series pulse secure gateway pulse connect secure ssl vpn and pulse secure unified access control uac as well as airwatch a leading third party enterprise grade mobile device management mdm solution. Cross site scripting xss vulnerability in the ssl vpn uac web server in the juniper junos pulse secure access service ssl vpn devices with ive os 7 1 before 7 1r16 7 4 before 7 4r3 and 8 0 before 8 0r1 and the juniper junos pulse access control service devices with uac os 4 1 before 4 1r8 4 4 before 4 4r3 and 5 0 before 5 0r1.