CVE-2014-3823 describes a clickjacking vulnerability affecting Juniper Junos Pulse Secure Access Service (SSL VPN) devices running IVE OS versions 8.0 prior to 8.0r1, 7.4 prior to 7.4r5, and 7.1 prior to 7.1r18. This medium-severity vulnerability (CVSS 4.3) allows remote attackers to perform clickjacking attacks, potentially leading to unauthorized actions or information disclosure, with a network attack vector and medium attack complexity. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage regarding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
7.1CPE matchmatch criteria | cpe:2.3:a:juniper:junos_pulse_secure_access_service:7.1:*:*:*:*:*:*:* | ||
7.1r1.1CPE matchmatch criteria | cpe:2.3:a:juniper:junos_pulse_secure_access_service:7.1r1.1:*:*:*:*:*:*:* | ||
7.1r2CPE matchmatch criteria | cpe:2.3:a:juniper:junos_pulse_secure_access_service:7.1r2:*:*:*:*:*:*:* | ||
7.1r3CPE matchmatch criteria | cpe:2.3:a:juniper:junos_pulse_secure_access_service:7.1r3:*:*:*:*:*:*:* | ||
7.1r4CPE matchmatch criteria | cpe:2.3:a:juniper:junos_pulse_secure_access_service:7.1r4:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:N/I:P/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.