cancel
Showing results for 
Search instead for 
Did you mean: 

US Cert - Clientless SSL-VPN vulnerability - any thoughts or comments

muttbarker_
Valued Contributor

US Cert - Clientless SSL-VPN vulnerability - any thoughts or comments

US Cert - "US Computer Emergency Readiness Team" issued a vulnerability advisory on clientless SSL VPN's including Juniper. http://www.kb.cert.org/vuls/id/261869

Just curious if anyone has taken a look at it and had any thoughts on it. It seems to me that while it does outline a potential threat it is very easily dealt with and really not that much of an issue.

I have had a few calls from very security concerned customers already on this one and was wondering what my fellow SSL geeks think about this.

1 REPLY 1
cbarcellos_
Regular Contributor

Re: US Cert - Clientless SSL-VPN vulnerability - any thoughts or comments

This Juniper KB has a few remediations to the vulnerability:

http://kb.pulsesecure.net/KB15799