MidnightBSD

Advisories for pulsesecure

CVE-2016-0799 HIGH

The fmtstr function in crypto/bio/b_print.c in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g improperly calculates string lengths, which allows remote attackers to cause a denial of service (overflow and out-of-bounds read) or possibly have unspecified other impact via a long string, as demonstrated by a large amount of ASN.1 data, a different vulnerability than CVE-2016-2842.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
openssl openssl 1.0.1p
openssl openssl 1.0.1o
openssl openssl 1.0.1
openssl openssl 1.0.1r
openssl openssl 1.0.1f
pulsesecure steel_belted_radius -
openssl openssl 1.0.1h
openssl openssl 1.0.1j
openssl openssl 1.0.1c
openssl openssl 1.0.2c
openssl openssl 1.0.1b
openssl openssl 1.0.1l
openssl openssl 1.0.2a
openssl openssl 1.0.2d
openssl openssl 1.0.1m
openssl openssl 1.0.2b
openssl openssl 1.0.1q
openssl openssl 1.0.1i
openssl openssl 1.0.1e
openssl openssl 1.0.1k
openssl openssl 1.0.2e
openssl openssl 1.0.1d
openssl openssl 1.0.1n
openssl openssl 1.0.2
openssl openssl 1.0.1g
openssl openssl 1.0.2f
pulsesecure client -
openssl openssl 1.0.1a
CVE-2016-0800 MEDIUM

The SSLv2 protocol, as used in OpenSSL before 1.0.1s and 1.0.2 before 1.0.2g and other products, requires a server to send a ServerVerify message before establishing that a client possesses certain plaintext RSA data, which makes it easier for remote attackers to decrypt TLS ciphertext data by leveraging a Bleichenbacher RSA padding oracle, aka a "DROWN" attack.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,CWE-310,

Products Affected

Vendor Product Version
openssl openssl 1.0.1p
openssl openssl 1.0.1o
openssl openssl 1.0.1
openssl openssl 1.0.1r
openssl openssl 1.0.1f
pulsesecure steel_belted_radius -
openssl openssl 1.0.1h
openssl openssl 1.0.1j
openssl openssl 1.0.1c
openssl openssl 1.0.2c
openssl openssl 1.0.1b
openssl openssl 1.0.1l
openssl openssl 1.0.2a
openssl openssl 1.0.2d
openssl openssl 1.0.1m
openssl openssl 1.0.2b
openssl openssl 1.0.1q
openssl openssl 1.0.1i
openssl openssl 1.0.1e
openssl openssl 1.0.1k
openssl openssl 1.0.2e
openssl openssl 1.0.1d
openssl openssl 1.0.1n
openssl openssl 1.0.2
openssl openssl 1.0.1g
openssl openssl 1.0.2f
pulsesecure client -
openssl openssl 1.0.1a
CVE-2016-2408 HIGH

Pulse Secure Desktop before 5.2R2 and Pulse Secure Installer Service before 8.2R2 and below for Windows allow restricted users to gain privileges via unspecified vectors.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-264,

Products Affected

Vendor Product Version
pulsesecure standalone_pulse_installer_service 8.0r2.0
pulsesecure pulse_secure_security 8.1r5.0
pulsesecure pulse_secure_desktop 5.1r3.0
pulsesecure pulse_secure_security 8.0r5.0
pulsesecure pulse_secure_desktop 5.0r5.0
pulsesecure standalone_pulse_installer_service 8.1r4.0
pulsesecure pulse_secure_desktop 5.0r4.0
pulsesecure standalone_pulse_installer_service 7.4r5.0
pulsesecure standalone_pulse_installer_service 7.4r13.2
pulsesecure pulse_secure_desktop 5.0r7.0
pulsesecure standalone_pulse_installer_service 7.4r9.2
pulsesecure standalone_pulse_installer_service 7.4r13.4
pulsesecure pulse_secure_desktop 5.0r8.1
pulsesecure standalone_pulse_installer_service 7.4r13.1
pulsesecure pulse_secure_security 8.0r15.0
pulsesecure pulse_secure_security 8.2r1.0
pulsesecure pulse_secure_security 8.0r2.0
pulsesecure standalone_pulse_installer_service 7.4r3.0
pulsesecure pulse_secure_security 8.0r1.0
pulsesecure pulse_secure_desktop 5.0r13.0
pulsesecure pulse_secure_desktop 5.1r5.1
pulsesecure standalone_pulse_installer_service 8.0r3.1
pulsesecure pulse_secure_security 8.1r1.1
pulsesecure pulse_secure_desktop 5.1r8.0
pulsesecure standalone_pulse_installer_service 8.0r7.0
pulsesecure standalone_pulse_installer_service 8.0r13.1
pulsesecure standalone_pulse_installer_service 8.1r3.2
pulsesecure pulse_secure_security 8.1r6.0
pulsesecure pulse_secure_desktop 5.1r9.0
pulsesecure pulse_secure_security 8.0r4.1
pulsesecure standalone_pulse_installer_service 7.4r12.0
pulsesecure standalone_pulse_installer_service 8.0r4.1
pulsesecure standalone_pulse_installer_service 8.0r3.0
pulsesecure standalone_pulse_installer_service 8.1r2.1
pulsesecure pulse_secure_security 8.0r3.0
pulsesecure standalone_pulse_installer_service 8.0r8.1
pulsesecure pulse_secure_security 8.0r7.0
pulsesecure standalone_pulse_installer_service 8.0r7.1
pulsesecure pulse_secure_security 8.0r7.1
pulsesecure pulse_secure_security 8.1r1.0
pulsesecure pulse_secure_security 8.0r4.0
pulsesecure standalone_pulse_installer_service 7.4r9.1
pulsesecure pulse_secure_security 8.1r7.0
pulsesecure pulse_secure_desktop 5.0r3.1
pulsesecure pulse_secure_security 8.1r9.0
pulsesecure standalone_pulse_installer_service 8.1r1.1
pulsesecure standalone_pulse_installer_service 8.0r15.0
pulsesecure standalone_pulse_installer_service 8.0r3.2
pulsesecure standalone_pulse_installer_service 7.4r9.3
pulsesecure standalone_pulse_installer_service 8.0r1.1
pulsesecure standalone_pulse_installer_service 8.0r6.0
pulsesecure standalone_pulse_installer_service 8.0r12.1
pulsesecure standalone_pulse_installer_service 8.1r3.1
pulsesecure standalone_pulse_installer_service 8.0r1.0
pulsesecure standalone_pulse_installer_service 8.1r6.0
pulsesecure pulse_secure_security 8.0r8.0
pulsesecure standalone_pulse_installer_service 7.4r2.0
pulsesecure pulse_secure_security 8.1r2.1
pulsesecure standalone_pulse_installer_service 7.4r8.0
pulsesecure standalone_pulse_installer_service 8.0r10.0
pulsesecure standalone_pulse_installer_service 8.0r11.0
pulsesecure odyssey_access_client *
pulsesecure standalone_pulse_installer_service 7.4r13.3
pulsesecure pulse_secure_desktop 5.0r9.0
pulsesecure pulse_secure_security 8.1r2.0
pulsesecure pulse_secure_security 8.1r4.1
pulsesecure pulse_secure_security 8.1r3.2
pulsesecure standalone_pulse_installer_service 8.2r1.1
pulsesecure standalone_pulse_installer_service 8.0r8.0
pulsesecure pulse_secure_desktop 5.1r6.0
pulsesecure standalone_pulse_installer_service 7.4r10.0
pulsesecure standalone_pulse_installer_service 7.4r9.0
pulsesecure pulse_secure_desktop 5.1r5.0
pulsesecure pulse_secure_security 8.0r1.1
pulsesecure pulse_secure_desktop 5.0r6.0
pulsesecure pulse_secure_security 8.1r3.1
pulsesecure standalone_pulse_installer_service 7.4r1.0
pulsesecure pulse_secure_desktop 5.0r15.0
pulsesecure pulse_secure_security 8.2r1.1
pulsesecure standalone_pulse_installer_service 7.4r4.0
pulsesecure standalone_pulse_installer_service 8.0r13.0
pulsesecure pulse_secure_desktop 5.2r1.0
pulsesecure pulse_secure_security 8.0r3.2
pulsesecure pulse_secure_desktop 5.0r14.0
pulsesecure standalone_pulse_installer_service 7.4r6.0
pulsesecure pulse_secure_desktop 5.1r1.0
pulsesecure standalone_pulse_installer_service 8.1r9.0
pulsesecure standalone_pulse_installer_service 8.1r5.0
pulsesecure pulse_secure_desktop 5.2r1.1
pulsesecure pulse_secure_security 8.0r12.1
pulsesecure pulse_secure_security 8.0r6.0
pulsesecure pulse_secure_desktop 5.0r10.0
pulsesecure pulse_secure_security 8.2r2.0
pulsesecure standalone_pulse_installer_service 8.1r3.0
pulsesecure standalone_pulse_installer_service 8.1r4.1
pulsesecure pulse_secure_desktop 5.0r13.1
pulsesecure pulse_secure_security 8.0r13.0
pulsesecure pulse_secure_desktop 5.0r8.0
pulsesecure standalone_pulse_installer_service 7.4r13.6
pulsesecure standalone_pulse_installer_service 8.2r1.0
pulsesecure standalone_pulse_installer_service 8.1r1.0
pulsesecure pulse_secure_desktop 5.0r11.0
pulsesecure pulse_secure_desktop 5.0r4.1
pulsesecure pulse_secure_desktop 5.0r2.0
pulsesecure pulse_secure_security 8.0r3.1
pulsesecure pulse_secure_security 8.0r9.0
pulsesecure pulse_secure_desktop 5.1r3.2
pulsesecure standalone_pulse_installer_service 7.4r13.0
pulsesecure pulse_secure_security 8.0r8.1
pulsesecure pulse_secure_desktop 5.1r4.0
pulsesecure pulse_secure_security 8.0r10.0
pulsesecure standalone_pulse_installer_service 8.1r2.0
pulsesecure standalone_pulse_installer_service 8.0r14.0
pulsesecure pulse_secure_desktop 5.0r1.0
pulsesecure pulse_secure_desktop 5.2r2.0
pulsesecure pulse_secure_security 8.0r13.1
pulsesecure standalone_pulse_installer_service 8.1r7.0
pulsesecure standalone_pulse_installer_service 8.2r2.0
pulsesecure standalone_pulse_installer_service 7.4r13.5
pulsesecure pulse_secure_security 8.1r4.0
pulsesecure standalone_pulse_installer_service 7.4r11.1
pulsesecure pulse_secure_security 8.0r14.0
pulsesecure pulse_secure_desktop 5.1r1.1
pulsesecure standalone_pulse_installer_service 8.1r8.0
pulsesecure pulse_secure_security 8.1r3.0
pulsesecure pulse_secure_desktop 5.0r3.0
pulsesecure pulse_secure_desktop 5.0r12.0
pulsesecure standalone_pulse_installer_service 8.0r5.0
pulsesecure pulse_secure_desktop 5.1r2.0
pulsesecure pulse_secure_desktop 5.1r3.1
pulsesecure pulse_secure_security 8.0r11.0
pulsesecure pulse_secure_desktop 5.1r7.0
pulsesecure standalone_pulse_installer_service 8.0r9.0
pulsesecure pulse_secure_security 8.1r8.0
pulsesecure standalone_pulse_installer_service 7.4r11.0
pulsesecure standalone_pulse_installer_service 7.4r7.0
pulsesecure standalone_pulse_installer_service 8.0r4.0
CVE-2016-3985 LOW

The Terminal Services Remote Desktop Protocol (RDP) client session restrictions feature in Pulse Connect Secure (aka PCS) 8.1R7 and 8.2R1 allow remote authenticated users to bypass intended access restrictions via unspecified vectors.

CVSS 2.0

Severity: LOW

Problem Type: CWE-284,

Products Affected

Vendor Product Version
pulsesecure pulse_connect_secure 8.1r7
pulsesecure pulse_connect_secure 8.2r1
CVE-2016-4786 HIGH

Pulse Connect Secure (PCS) 8.2 before 8.2r1, 8.1 before 8.1r3, 8.0 before 8.0r11, and 7.4 before 7.4r13.4 allow remote attackers to cause a denial of service (CPU consumption) via unspecified vectors.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ivanti connect_secure 8.1
pulsesecure pulse_connect_secure 8.1r1.0
pulsesecure pulse_connect_secure 7.4
ivanti connect_secure 8.0
ivanti connect_secure 8.2
CVE-2016-4787 MEDIUM

Pulse Connect Secure (PCS) 8.2 before 8.2r1, 8.1 before 8.1r2, 8.0 before 8.0r10, and 7.4 before 7.4r13.4 allow remote attackers to read sensitive system authentication files in an unspecified directory via unknown vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ivanti connect_secure 8.1
pulsesecure pulse_connect_secure 8.1r1.0
pulsesecure pulse_connect_secure 7.4
ivanti connect_secure 8.0
ivanti connect_secure 8.2
CVE-2016-4788 MEDIUM

Pulse Connect Secure (PCS) 8.2 before 8.2r1, 8.1 before 8.1r2, 8.0 before 8.0r10, and 7.4 before 7.4r13.4 allow remote attackers to read an unspecified system file via unknown vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ivanti connect_secure 8.1
pulsesecure pulse_connect_secure 8.1r1.0
pulsesecure pulse_connect_secure 7.4
ivanti connect_secure 8.0
ivanti connect_secure 8.2
CVE-2016-4789 MEDIUM

Cross-site scripting (XSS) vulnerability in the system configuration section in the administrative user interface in Pulse Connect Secure (PCS) 8.2 before 8.2r1, 8.1 before 8.1r2, 8.0 before 8.0r9, and 7.4 before 7.4r13.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ivanti connect_secure 8.1
pulsesecure pulse_connect_secure 8.1r1.0
pulsesecure pulse_connect_secure 7.4
ivanti connect_secure 8.0
ivanti connect_secure 8.2
CVE-2016-4790 LOW

Cross-site scripting (XSS) vulnerability in the administrative user interface in Pulse Connect Secure (PCS) 8.2 before 8.2r1, 8.1 before 8.1r2, 8.0 before 8.0r9, and 7.4 before 7.4r13.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ivanti connect_secure 8.1
pulsesecure pulse_connect_secure 8.1r1.0
pulsesecure pulse_connect_secure 7.4
ivanti connect_secure 8.0
ivanti connect_secure 8.2
CVE-2016-4791 MEDIUM

The administrative user interface in Pulse Connect Secure (PCS) 8.2 before 8.2r1, 8.1 before 8.1r2, 8.0 before 8.0r9, and 7.4 before 7.4r13.4 allows remote administrators to enumerate files, read arbitrary files, and conduct server side request forgery (SSRF) attacks via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ivanti connect_secure 8.1
pulsesecure pulse_connect_secure 8.1r1.0
pulsesecure pulse_connect_secure 7.4
ivanti connect_secure 8.0
ivanti connect_secure 8.2
CVE-2017-11193 MEDIUM

Pulse Connect Secure 8.3R1 has CSRF in diag.cgi. In the panel, the diag.cgi file is responsible for running commands such as ping, ping6, traceroute, traceroute6, nslookup, arp, and Portprobe. These functions do not have any protections against CSRF. That can allow an attacker to run these commands against any IP if they can get an admin to visit their malicious CSRF page.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
pulsesecure pulse_connect_secure 8.3r1.0
CVE-2017-11194 MEDIUM

Pulse Connect Secure 8.3R1 has Reflected XSS in adminservercacertdetails.cgi. In the admin panel, the certid parameter of adminservercacertdetails.cgi is reflected in the application's response and is not properly sanitized, allowing an attacker to inject tags. An attacker could come up with clever payloads to make the system run commands such as ping, ping6, traceroute, nslookup, arp, etc.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
pulsesecure pulse_connect_secure 8.3r1.0
CVE-2017-11195 MEDIUM

Pulse Connect Secure 8.3R1 has Reflected XSS in launchHelp.cgi. The helpLaunchPage parameter is reflected in an IFRAME element, if the value contains two quotes. It properly sanitizes quotes and tags, so one cannot simply close the src with a quote and inject after that. However, an attacker can use javascript: or data: to abuse this.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
pulsesecure pulse_connect_secure 8.3r1.0
CVE-2017-11196 MEDIUM

Pulse Connect Secure 8.3R1 has CSRF in logout.cgi. The logout function of the admin panel is not protected by any CSRF tokens, thus allowing an attacker to logout a user by making them visit a malicious web page.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
pulsesecure pulse_connect_secure 8.3r1.0
CVE-2017-11455 MEDIUM

diag.cgi in Pulse Connect Secure 8.2R1 through 8.2R5, 8.1R1 through 8.1R10 and Pulse Policy Secure 5.3R1 through 5.3R5, 5.2R1 through 5.2R8, and 5.1R1 through 5.1R10 allow remote attackers to hijack the authentication of administrators for requests to start tcpdump, related to the lack of anti-CSRF tokens.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
pulsesecure pulse_policy_secure 5.2r1.0
pulsesecure pulse_connect_secure 8.1r1.0
pulsesecure pulse_policy_secure 5.3r5.1
pulsesecure pulse_policy_secure 5.3r1.0
pulsesecure pulse_policy_secure 5.3r3.1
pulsesecure pulse_policy_secure 5.1r3.0
pulsesecure pulse_policy_secure 5.2r7.0
pulsesecure pulse_policy_secure 5.3r8.0
pulsesecure pulse_policy_secure 5.3r4.0
pulsesecure pulse_policy_secure 5.2r5.0
pulsesecure pulse_policy_secure 5.2r7.1
pulsesecure pulse_connect_secure 8.2r3.0
pulsesecure pulse_policy_secure 5.3r5.0
pulsesecure pulse_policy_secure 5.2r3.2
pulsesecure pulse_policy_secure 5.1r6.0
pulsesecure pulse_policy_secure 5.2r2.0
pulsesecure pulse_connect_secure 8.2r4.1
pulsesecure pulse_policy_secure 5.1r8.0
pulsesecure pulse_policy_secure 5.1r1.0
pulsesecure pulse_policy_secure 5.3r1.1
pulsesecure pulse_policy_secure 5.3r7.0
pulsesecure pulse_policy_secure 5.1r7.1
pulsesecure pulse_connect_secure 8.2r2.0
pulsesecure pulse_policy_secure 5.2r8.0
pulsesecure pulse_policy_secure 5.3r6.0
pulsesecure pulse_policy_secure 5.2r3.0
pulsesecure pulse_policy_secure 5.3r3.0
pulsesecure pulse_connect_secure 8.2r1.0
pulsesecure pulse_policy_secure 5.3r2.0
pulsesecure pulse_policy_secure 5.1r1.1
pulsesecure pulse_policy_secure 5.3r5.2
pulsesecure pulse_policy_secure 5.1r3.2
pulsesecure pulse_policy_secure 5.1r2.1
pulsesecure pulse_policy_secure 5.1r9.1
pulsesecure pulse_policy_secure 5.1r4.0
pulsesecure pulse_connect_secure 8.2r3.1
pulsesecure pulse_policy_secure 5.1r2.0
ivanti connect_secure 8.1
pulsesecure pulse_connect_secure 8.2r5.0
pulsesecure pulse_connect_secure 8.2r4.0
pulsesecure pulse_policy_secure 5.2r4.0
pulsesecure pulse_policy_secure 5.2r6.0
pulsesecure pulse_policy_secure 5.3r4.1
pulsesecure pulse_connect_secure 8.2r1.1
pulsesecure pulse_policy_secure 5.1r10
pulsesecure pulse_policy_secure 5.1r5.0
pulsesecure pulse_policy_secure 5.1r7.0
CVE-2017-14935 MEDIUM

Pulse Secure Pulse One On-Premise 2.0.1649 and below does not properly validate requests, which allows remote users to query and obtain sensitive information.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
pulsesecure pulse_one_on-premise 2.0.1649
CVE-2017-17947 LOW

A cross site scripting issue has been found in custompage.cgi in Pulse Secure Pulse Connect Secure (PCS) before 8.0R17.0, 8.1.x before 8.1R13, 8.2.x before 8.2R9, and 8.3.x before 8.3R3 and Pulse Policy Secure (PPS) before 5.2R10, 5.3.x before 5.3R9, and 5.4.x before 5.4R3 due to one of the URL parameters not being sanitized. Exploitation does require the user to be logged in as administrator; the issue is not applicable to the end user portal.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
pulsesecure pulse_connect_secure *
CVE-2018-11002 MEDIUM

Pulse Secure Desktop Client 5.3 up to and including R6.0 build 1769 on Windows has Insecure Permissions.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-732,

Products Affected

Vendor Product Version
pulsesecure pulse_secure_desktop_client 5.3r4
pulsesecure pulse_secure_desktop_client 5.3r5.2
pulsesecure pulse_secure_desktop_client 5.3r1.1
pulsesecure pulse_secure_desktop_client 5.3r2
pulsesecure pulse_secure_desktop_client 5.3r4.2
pulsesecure pulse_secure_desktop_client 5.3r3
pulsesecure pulse_secure_desktop_client 5.3r1
pulsesecure pulse_secure_desktop_client 5.3r4.1
pulsesecure pulse_secure_desktop_client 5.3r5
pulsesecure pulse_secure_desktop_client 5.3r6
CVE-2018-14366 MEDIUM

download.cgi in Pulse Secure Pulse Connect Secure 8.1RX before 8.1R13 and 8.3RX before 8.3R4 and Pulse Policy Secure through 5.2RX before 5.2R10 and 5.4RX before 5.4R4 have an Open Redirect Vulnerability.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-601,

Products Affected

Vendor Product Version
pulsesecure pulse_policy_secure 5.2r1.0
pulsesecure pulse_connect_secure 8.1r1.0
pulsesecure pulse_policy_secure 5.2r9.1
pulsesecure pulse_policy_secure 5.4r3
pulsesecure pulse_policy_secure 5.2r7.0
pulsesecure pulse_policy_secure 5.4r1
pulsesecure pulse_policy_secure 5.2r9.0
pulsesecure pulse_policy_secure 5.2r5.0
pulsesecure pulse_policy_secure 5.2r7.1
pulsesecure pulse_policy_secure 5.4r2
pulsesecure pulse_connect_secure 8.3rx
pulsesecure pulse_policy_secure 5.2r3.2
ivanti connect_secure 8.3
pulsesecure pulse_policy_secure 5.2r2.0
ivanti connect_secure 8.1
pulsesecure pulse_policy_secure 5.4r2.1
pulsesecure pulse_policy_secure 5.2rx
pulsesecure pulse_policy_secure 5.2r4.0
pulsesecure pulse_policy_secure 5.4rx
pulsesecure pulse_policy_secure 5.2r6.0
pulsesecure pulse_policy_secure 5.2r8.0
pulsesecure pulse_policy_secure 5.2r3.0
pulsesecure pulse_connect_secure 8.1rx
CVE-2018-15726 MEDIUM

The Pulse Secure Desktop (macOS) 5.3RX before 5.3R5 and 9.0R1 has a Privilege Escalation Vulnerability.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-78,

Products Affected

Vendor Product Version
pulsesecure pulse_secure_desktop_client 5.3r4
pulsesecure pulse_secure_desktop_client 5.3r1.1
pulsesecure pulse_secure_desktop_client 5.3r2
pulsesecure pulse_secure_desktop_client 5.3r4.2
pulsesecure pulse_secure_desktop_client 5.3r3
pulsesecure pulse_secure_desktop_client 5.3rx
pulsesecure pulse_secure_desktop_client 5.3r1
pulsesecure pulse_secure_desktop_client 9.0r1
pulsesecure pulse_secure_desktop_client 5.3r4.1
CVE-2018-15749 LOW

The Pulse Secure Desktop (macOS) 5.3RX before 5.3R5 and 9.0R1 has a Format String Vulnerability.

CVSS 2.0

Severity: LOW

Problem Type: CWE-134,

Products Affected

Vendor Product Version
pulsesecure pulse_secure_desktop_client 5.3r4
pulsesecure pulse_secure_desktop_client 5.3r1.1
pulsesecure pulse_secure_desktop_client 5.3r2
pulsesecure pulse_secure_desktop_client 5.3r4.2
pulsesecure pulse_secure_desktop_client 5.3r3
pulsesecure pulse_secure_desktop_client 5.3rx
pulsesecure pulse_secure_desktop_client 5.3r1
pulsesecure pulse_secure_desktop_client 9.0r1
pulsesecure pulse_secure_desktop_client 5.3r4.1
CVE-2018-15865 MEDIUM

The Pulse Secure Desktop (macOS) has a Privilege Escalation Vulnerability.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
pulsesecure pulse_secure_desktop_client 5.1r6.0
pulsesecure pulse_secure_desktop_client 5.3r1.1
pulsesecure pulse_secure_desktop_client 5.3r3
pulsesecure pulse_secure_desktop_client 5.3r1
pulsesecure pulse_secure_desktop_client 5.1r7.0
pulsesecure pulse_secure_desktop_client 5.1r1.0
pulsesecure pulse_secure_desktop_client 5.1r3.0
pulsesecure pulse_secure_desktop_client 5.1r1.1
pulsesecure pulse_secure_desktop_client 5.1r5.1
pulsesecure pulse_secure_desktop_client 5.1r3.2
pulsesecure pulse_secure_desktop_client 5.3r2
pulsesecure pulse_secure_desktop_client 5.1r9.1
pulsesecure pulse_secure_desktop_client 5.1r10.0
pulsesecure pulse_secure_desktop_client 5.3r5
pulsesecure pulse_secure_desktop_client 5.1r4.0
pulsesecure pulse_secure_desktop_client 5.1r2.0
pulsesecure pulse_secure_desktop_client 5.3r4
pulsesecure pulse_secure_desktop_client 5.3r5.2
pulsesecure pulse_secure_desktop_client 5.1r5.0
pulsesecure pulse_secure_desktop_client 5.1r9.0
pulsesecure pulse_secure_desktop_client 5.1r8.0
pulsesecure pulse_secure_desktop_client 5.3r4.2
pulsesecure pulse_secure_desktop_client 5.1rx
pulsesecure pulse_secure_desktop_client 5.3r4.1
pulsesecure pulse_secure_desktop_client 5.1r3.1
CVE-2018-15909 MEDIUM

In Artifex Ghostscript 9.23 before 2018-08-24, a type confusion using the .shfill operator could be used by attackers able to supply crafted PostScript files to crash the interpreter or potentially execute code.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-704,

Products Affected

Vendor Product Version
canonical ubuntu_linux 16.04
redhat enterprise_linux_desktop 7.0
redhat enterprise_linux_server 7.0
artifex ghostscript *
artifex gpl_ghostscript *
redhat enterprise_linux_server_aus 7.6
redhat enterprise_linux_server_tus 7.6
redhat enterprise_linux_server_eus 7.6
canonical ubuntu_linux 18.04
pulsesecure pulse_connect_secure *
debian debian_linux 8.0
redhat enterprise_linux_workstation 7.0
canonical ubuntu_linux 14.04
CVE-2018-15910 MEDIUM

In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use a type confusion in the LockDistillerParams parameter to crash the interpreter or execute code.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-704,

Products Affected

Vendor Product Version
debian debian_linux 9.0
canonical ubuntu_linux 16.04
redhat enterprise_linux_desktop 7.0
redhat enterprise_linux_server 7.0
artifex ghostscript *
artifex gpl_ghostscript *
redhat enterprise_linux_server_eus 7.5
canonical ubuntu_linux 18.04
pulsesecure pulse_connect_secure *
debian debian_linux 8.0
redhat enterprise_linux_workstation 7.0
canonical ubuntu_linux 14.04
CVE-2018-15911 MEDIUM

In Artifex Ghostscript 9.23 before 2018-08-24, attackers able to supply crafted PostScript could use uninitialized memory access in the aesdecode operator to crash the interpreter or potentially execute code.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-908,

Products Affected

Vendor Product Version
debian debian_linux 9.0
canonical ubuntu_linux 16.04
redhat enterprise_linux_desktop 7.0
redhat enterprise_linux_server 7.0
artifex ghostscript *
artifex gpl_ghostscript *
redhat enterprise_linux_server_aus 7.6
redhat enterprise_linux_server_tus 7.6
redhat enterprise_linux_server_eus 7.6
canonical ubuntu_linux 18.04
pulsesecure pulse_connect_secure *
debian debian_linux 8.0
redhat enterprise_linux_workstation 7.0
canonical ubuntu_linux 14.04
CVE-2018-16261 MEDIUM

In Pulse Secure Pulse Desktop Client 5.3RX before 5.3R5 and 9.0R1, there is a Privilege Escalation Vulnerability with Dynamic Certificate Trust.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-295,

Products Affected

Vendor Product Version
pulsesecure pulse_secure_desktop_client 5.3r4
pulsesecure pulse_secure_desktop_client 5.3r1.1
pulsesecure pulse_secure_desktop_client 5.3r2
pulsesecure pulse_secure_desktop_client 5.3r4.2
pulsesecure pulse_secure_desktop_client 5.3r3
pulsesecure pulse_secure_desktop_client 5.3rx
pulsesecure pulse_secure_desktop_client 5.3r1
pulsesecure pulse_secure_desktop_client 9.0r1
pulsesecure pulse_secure_desktop_client 5.3r4.1
CVE-2018-16513 MEDIUM

In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use a type confusion in the setcolor function to crash the interpreter or possibly have unspecified other impact.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-704,

Products Affected

Vendor Product Version
debian debian_linux 9.0
canonical ubuntu_linux 16.04
artifex ghostscript *
artifex gpl_ghostscript *
canonical ubuntu_linux 18.04
pulsesecure pulse_connect_secure *
debian debian_linux 8.0
canonical ubuntu_linux 14.04
CVE-2018-18284 MEDIUM

Artifex Ghostscript 9.25 and earlier allows attackers to bypass a sandbox protection mechanism via vectors involving the 1Policy operator.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
debian debian_linux 9.0
canonical ubuntu_linux 16.04
redhat enterprise_linux_desktop 7.0
redhat enterprise_linux_server 7.0
artifex ghostscript *
artifex gpl_ghostscript *
canonical ubuntu_linux 18.10
redhat enterprise_linux_server_aus 7.6
redhat enterprise_linux_server_tus 7.6
redhat enterprise_linux_server_eus 7.6
canonical ubuntu_linux 18.04
pulsesecure pulse_connect_secure *
debian debian_linux 8.0
redhat enterprise_linux_workstation 7.0
canonical ubuntu_linux 14.04
CVE-2018-20193 MEDIUM

Certain Secure Access SA Series SSL VPN products (originally developed by Juniper Networks but now sold and supported by Pulse Secure, LLC) allow privilege escalation, as demonstrated by Secure Access SSL VPN SA-4000 5.1R5 (build 9627) 4.2 Release (build 7631). This occurs because appropriate controls are not performed. Specifically, it is possible for a readonly user to change the administrator user password by making a local copy of the /dana-admin/user/update.cgi page, changing the "user" value, and saving the changes.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-269,

Products Affected

Vendor Product Version
pulsesecure secure_access_series_ssl_vpn_sa-4000 4.2
pulsesecure secure_access_series_ssl_vpn_sa-4000 5.1r5
CVE-2018-20306 LOW

A stored cross-site scripting (XSS) vulnerability in the web administration user interface of Pulse Secure Virtual Traffic Manager may allow a remote authenticated attacker to inject web script or HTML via a crafted website and steal sensitive data and credentials. Affected releases are Pulse Secure Virtual Traffic Manager 9.9 versions prior to 9.9r2 and 10.4r1.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
pulsesecure virtual_traffic_manager *
CVE-2018-20307 MEDIUM

Pulse Secure Virtual Traffic Manager 9.9 versions prior to 9.9r2 and 10.4r1 allow a remote authenticated user to obtain sensitive historical activity information by leveraging incorrect permission validation.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 4.3 MEDIUM CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N 2.8 1.4

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
pulsesecure virtual_traffic_manager 17.2
pulsesecure virtual_traffic_manager 10.4
pulsesecure virtual_traffic_manager 9.9
CVE-2018-20809 MEDIUM

A crafted message can cause the web server to crash with Pulse Secure Pulse Connect Secure (PCS) 8.3RX before 8.3R5 and Pulse Policy Secure 5.4RX before 5.4R5. This is not applicable to PCS 8.1RX.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
pulsesecure pulse_policy_secure 5.1
pulsesecure pulse_policy_secure 5.3
pulsesecure pulse_policy_secure 5.2
pulsesecure pulse_policy_secure 4.4
pulsesecure pulse_policy_secure 5.4
ivanti connect_secure 8.3
pulsesecure pulse_policy_secure 5.0
CVE-2018-20810 HIGH

Session data between cluster nodes during cluster synchronization is not properly encrypted in Pulse Secure Pulse Connect Secure (PCS) 8.3RX before 8.3R2 and Pulse Policy Secure (PPS) 5.4RX before 5.4R2. This is not applicable to PCS 8.1RX, PPS 5.2RX, or stand-alone devices.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-326,

Products Affected

Vendor Product Version
pulsesecure pulse_policy_secure 5.4
ivanti connect_secure 8.3
CVE-2018-20812 MEDIUM

An information exposure issue where IPv6 DNS traffic would be sent outside of the VPN tunnel (when Traffic Enforcement was enabled) exists in Pulse Secure Pulse Secure Desktop 9.0R1 and below. This is applicable only to dual-stack (IPv4/IPv6) endpoints.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
pulsesecure pulse_secure_desktop_client 5.1
pulsesecure pulse_secure_desktop_client 5.3
pulsesecure pulse_secure_desktop_client 9.0
pulsesecure pulse_secure_desktop_client 4.0
pulsesecure pulse_secure_desktop_client 5.1r
CVE-2018-20814 MEDIUM

An XSS issue was found with Psaldownload.cgi in Pulse Secure Pulse Connect Secure (PCS) 8.3R2 before 8.3R2 and Pulse Policy Secure (PPS) 5.4RX before 5.4R2. This is not applicable to PCS 8.1RX or PPS 5.2RX.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
pulsesecure pulse_policy_secure 5.4
ivanti connect_secure 8.3
CVE-2018-5299 HIGH

A stack-based Buffer Overflow Vulnerability exists in the web server in Pulse Secure Pulse Connect Secure (PCS) before 8.3R4 and Pulse Policy Secure (PPS) before 5.4R4, leading to memory corruption and possibly remote code execution.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-787,

Products Affected

Vendor Product Version
pulsesecure pulse_policy_secure *
pulsesecure pulse_connect_secure *
CVE-2018-6320 HIGH

A vulnerability has been discovered in login.cgi in Pulse Secure Pulse Connect Secure (PCS) 8.1RX before 8.1R12 and 8.3RX before 8.3R2 and Pulse Policy Secure (PPS) 5.2RX before 5.2R9 and 5.4RX before 5.4R2 wherein an http(s) Host header received from the browser is trusted without validation.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-20,

Products Affected

Vendor Product Version
pulsesecure pulse_policy_secure 5.2r1.0
pulsesecure pulse_connect_secure 8.1r1.0
pulsesecure pulse_policy_secure 5.2r7.0
pulsesecure pulse_policy_secure 5.4r1
pulsesecure pulse_policy_secure 5.2r5.0
pulsesecure pulse_policy_secure 5.2r7.1
pulsesecure pulse_policy_secure 5.4r2
pulsesecure pulse_connect_secure 8.3rx
pulsesecure pulse_policy_secure 5.2r3.2
pulsesecure pulse_policy_secure 5.2r2.0
ivanti connect_secure 8.1
pulsesecure pulse_policy_secure 5.2rx
pulsesecure pulse_policy_secure 5.2r4.0
pulsesecure pulse_policy_secure 5.4rx
pulsesecure pulse_policy_secure 5.2r6.0
pulsesecure pulse_policy_secure 5.2r8.0
pulsesecure pulse_policy_secure 5.2r3.0
pulsesecure pulse_connect_secure 8.1rx
CVE-2018-6374 MEDIUM

The GUI component (aka PulseUI) in Pulse Secure Desktop Linux clients before PULSE5.2R9.2 and 5.3.x before PULSE5.3R4.2 does not perform strict SSL Certificate Validation. This can lead to the manipulation of the Pulse Connection set.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-295,

Products Affected

Vendor Product Version
pulsesecure desktop_linux_client *
CVE-2018-7572 HIGH

Pulse Secure Client 9.0R1 and 5.3RX before 5.3R5, when configured to authenticate VPN users during Windows Logon, can allow attackers to bypass Windows authentication and execute commands on the system with the privileges of Pulse Secure Client. The attacker must interrupt the client's network connectivity, and trigger a connection to a crafted proxy server with an invalid SSL certificate that allows certification-manager access, leading to the ability to browse local files and execute local programs.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-287,

Products Affected

Vendor Product Version
pulsesecure pulse_secure_desktop 5.3r1.0
pulsesecure pulse_secure_desktop 5.3r1.1
pulsesecure pulse_secure_desktop 5.3r4.0
pulsesecure pulse_secure_desktop 5.3r2.0
pulsesecure pulse_secure_desktop 5.3r4.1
pulsesecure pulse_secure_desktop 5.3r4.2
pulsesecure pulse_secure_desktop 9.0r1.0
pulsesecure pulse_secure_desktop 5.3rx
pulsesecure pulse_secure_desktop 5.3r3.0
CVE-2018-9849 MEDIUM

Pulse Secure Pulse Connect Secure 8.1.x before 8.1R14, 8.2.x before 8.2R11, and 8.3.x before 8.3R5 do not properly process nested XML entities, which allows remote attackers to cause a denial of service (memory consumption and memory errors) via a crafted XML document.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
pulsesecure pulse_connect_secure *
CVE-2019-11213 MEDIUM

In Pulse Secure Pulse Desktop Client and Network Connect, an attacker could access session tokens to replay and spoof sessions, and as a result, gain unauthorized access as an end user, a related issue to CVE-2019-1573. (The endpoint would need to be already compromised for exploitation to succeed.) This affects Pulse Desktop Client 5.x before Secure Desktop 5.3R7 and Pulse Desktop Client 9.x before Secure Desktop 9.0R3. It also affects (for Network Connect customers) Pulse Connect Secure 8.1 before 8.1R14, 8.3 before 8.3R7, and 9.0 before 9.0R3.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-384,

Products Affected

Vendor Product Version
ivanti connect_secure *
pulsesecure pulse_secure_desktop_client *
pulsesecure pulse_connect_secure *
CVE-2019-11477 HIGH

Jonathan Looney discovered that the TCP_SKB_CB(skb)->tcp_gso_segs value was subject to an integer overflow in the Linux kernel when handling TCP Selective Acknowledgments (SACKs). A remote attacker could use this to cause a denial of service. This has been fixed in stable kernel releases 4.4.182, 4.9.182, 4.14.127, 4.19.52, 5.1.11, and is fixed in commit 3b4929f65b0d8249f19a50245cd88ed1a2f78cff.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-190,CWE-190,

Products Affected

Vendor Product Version
f5 big-ip_analytics 15.0.0
pulsesecure pulse_policy_secure -
pulsesecure pulse_connect_secure -
canonical ubuntu_linux 18.10
f5 big-ip_analytics *
redhat enterprise_linux_atomic_host -
redhat enterprise_linux_aus 6.5
f5 big-ip_global_traffic_manager *
redhat enterprise_linux 7.0
f5 big-ip_link_controller *
f5 big-ip_edge_gateway *
f5 big-ip_advanced_firewall_manager *
f5 big-ip_local_traffic_manager 15.0.0
canonical ubuntu_linux 12.04
canonical ubuntu_linux 14.04
canonical ubuntu_linux 16.04
f5 big-ip_link_controller 15.0.0
f5 big-ip_fraud_protection_service 15.0.0
f5 big-ip_edge_gateway 15.0.0
f5 big-ip_local_traffic_manager *
redhat enterprise_linux 6.0
f5 big-ip_application_acceleration_manager 15.0.0
f5 big-ip_fraud_protection_service *
f5 traffix_signaling_delivery_controller *
f5 big-ip_webaccelerator *
redhat enterprise_linux 5.0
redhat enterprise_linux_aus 6.6
f5 big-ip_access_policy_manager *
f5 big-ip_advanced_firewall_manager 15.0.0
redhat enterprise_linux 8.0
f5 big-ip_webaccelerator 15.0.0
f5 big-ip_global_traffic_manager 15.0.0
canonical ubuntu_linux 19.04
redhat enterprise_linux_eus 7.4
f5 big-ip_policy_enforcement_manager 15.0.0
f5 big-ip_policy_enforcement_manager *
canonical ubuntu_linux 18.04
pulsesecure pulse_secure_virtual_application_delivery_controller -
f5 big-ip_domain_name_system 15.0.0
f5 traffix_sdc *
ivanti connect_secure -
linux linux_kernel *
f5 big-ip_application_acceleration_manager *
f5 big-ip_domain_name_system *
f5 big-ip_application_security_manager 15.0.0
f5 big-ip_application_security_manager *
redhat enterprise_mrg 2.0
f5 big-ip_access_policy_manager 15.0.0
redhat enterprise_linux_eus 7.5
CVE-2019-11478 MEDIUM

Jonathan Looney discovered that the TCP retransmission queue implementation in tcp_fragment in the Linux kernel could be fragmented when handling certain TCP Selective Acknowledgment (SACK) sequences. A remote attacker could use this to cause a denial of service. This has been fixed in stable kernel releases 4.4.182, 4.9.182, 4.14.127, 4.19.52, 5.1.11, and is fixed in commit f070ef2ac66716357066b683fb0baf55f8191a2e.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-770,CWE-400,

Products Affected

Vendor Product Version
f5 big-ip_analytics 15.0.0
pulsesecure pulse_policy_secure -
pulsesecure pulse_connect_secure -
canonical ubuntu_linux 18.10
f5 big-ip_analytics *
redhat enterprise_linux_atomic_host -
redhat enterprise_linux_aus 6.5
f5 big-ip_global_traffic_manager *
redhat enterprise_linux 7.0
f5 big-ip_link_controller *
f5 big-ip_edge_gateway *
f5 big-ip_advanced_firewall_manager *
f5 big-ip_local_traffic_manager 15.0.0
canonical ubuntu_linux 12.04
canonical ubuntu_linux 14.04
canonical ubuntu_linux 16.04
f5 big-ip_link_controller 15.0.0
f5 big-ip_fraud_protection_service 15.0.0
f5 big-ip_edge_gateway 15.0.0
f5 big-ip_local_traffic_manager *
redhat enterprise_linux 6.0
f5 big-ip_application_acceleration_manager 15.0.0
f5 big-ip_fraud_protection_service *
f5 traffix_signaling_delivery_controller *
f5 big-ip_webaccelerator *
redhat enterprise_linux 5.0
redhat enterprise_linux_aus 6.6
f5 big-ip_access_policy_manager *
f5 big-ip_advanced_firewall_manager 15.0.0
redhat enterprise_linux 8.0
f5 big-ip_webaccelerator 15.0.0
f5 big-ip_global_traffic_manager 15.0.0
canonical ubuntu_linux 19.04
redhat enterprise_linux_eus 7.4
f5 big-ip_policy_enforcement_manager 15.0.0
f5 big-ip_policy_enforcement_manager *
canonical ubuntu_linux 18.04
pulsesecure pulse_secure_virtual_application_delivery_controller -
f5 big-ip_domain_name_system 15.0.0
ivanti connect_secure -
linux linux_kernel *
f5 big-ip_application_acceleration_manager *
f5 big-ip_domain_name_system *
f5 big-ip_application_security_manager 15.0.0
f5 big-ip_application_security_manager *
redhat enterprise_mrg 2.0
f5 big-ip_access_policy_manager 15.0.0
redhat enterprise_linux_eus 7.5
CVE-2019-11507 MEDIUM

In Pulse Secure Pulse Connect Secure (PCS) 8.3.x before 8.3R7.1 and 9.0.x before 9.0R3, an XSS issue has been found on the Application Launcher page.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 6.1 MEDIUM CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N 2.8 2.7

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
pulsesecure pulse_connect_secure 9.0
ivanti connect_secure 8.3
pulsesecure pulse_connect_secure 8.3
ivanti connect_secure 9.0
CVE-2019-11508 MEDIUM

In Pulse Secure Pulse Connect Secure (PCS) before 8.1R15.1, 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an authenticated attacker (via the admin web interface) can exploit Directory Traversal to execute arbitrary code on the appliance.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 7.2 HIGH CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H 1.2 5.9

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-22,

Products Affected

Vendor Product Version
pulsesecure pulse_connect_secure 8.2
pulsesecure pulse_connect_secure 7.1
ivanti connect_secure 8.3
ivanti connect_secure 9.0
ivanti connect_secure 7.1
ivanti connect_secure 8.1
pulsesecure pulse_connect_secure 7.4
pulsesecure pulse_connect_secure 8.1
pulsesecure pulse_connect_secure 9.0
ivanti connect_secure 7.4
pulsesecure pulse_connect_secure 8.3
ivanti connect_secure 8.2
CVE-2019-11509 MEDIUM

In Pulse Secure Pulse Connect Secure (PCS) before 8.1R15.1, 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4 and Pulse Policy Secure (PPS) before 5.1R15.1, 5.2 before 5.2R12.1, 5.3 before 5.3R15.1, 5.4 before 5.4R7.1, and 9.0 before 9.0R3.2, an authenticated attacker (via the admin web interface) can exploit Incorrect Access Control to execute arbitrary code on the appliance.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 8.8 HIGH CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H 2.8 5.9

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
pulsesecure pulse_connect_secure 8.2
pulsesecure pulse_policy_secure 5.2
ivanti connect_secure 8.3
ivanti connect_secure 9.0
ivanti connect_secure 8.1
pulsesecure pulse_policy_secure 9.0
pulsesecure pulse_connect_secure 8.1
ivanti policy_secure 9.0
pulsesecure pulse_connect_secure 9.0
pulsesecure pulse_policy_secure 5.4
pulsesecure pulse_connect_secure 8.3
ivanti connect_secure 8.2
CVE-2019-11510 HIGH

In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthenticated remote attacker can send a specially crafted URI to perform an arbitrary file reading vulnerability .

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 10.0 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H 3.9 6.0

CVSS 2.0

Severity: HIGH

Problem Type: CWE-22,CWE-22,

Products Affected

Vendor Product Version
pulsesecure pulse_connect_secure 8.2
pulsesecure pulse_connect_secure 9.0
ivanti connect_secure 8.3
pulsesecure pulse_connect_secure 8.3
ivanti connect_secure 9.0
ivanti connect_secure 8.2
CVE-2019-11538 MEDIUM

In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1RX before 8.1R15.1, an NFS problem could allow an authenticated attacker to access the contents of arbitrary files on the affected device.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 7.7 HIGH CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N 3.1 4.0

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-59,

Products Affected

Vendor Product Version
ivanti connect_secure 8.1
pulsesecure pulse_connect_secure 8.2
pulsesecure pulse_connect_secure 8.1
pulsesecure pulse_connect_secure 9.0
ivanti connect_secure 8.3
pulsesecure pulse_connect_secure 8.3
ivanti connect_secure 9.0
ivanti connect_secure 8.2
CVE-2019-11539 MEDIUM

In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1RX before 8.1R15.1 and Pulse Policy Secure version 9.0RX before 9.0R3.2, 5.4RX before 5.4R7.1, 5.3RX before 5.3R12.1, 5.2RX before 5.2R12.1, and 5.1RX before 5.1R15.1, the admin web interface allows an authenticated attacker to inject and execute commands.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-78,CWE-78,

Products Affected

Vendor Product Version
pulsesecure pulse_policy_secure 5.2r1.0
pulsesecure pulse_connect_secure 8.1r1.0
pulsesecure pulse_policy_secure 5.4r3
pulsesecure pulse_policy_secure 5.3r1.0
pulsesecure pulse_connect_secure 8.2
pulsesecure pulse_policy_secure 5.4r1
pulsesecure pulse_policy_secure 5.3r5.0
pulsesecure pulse_policy_secure 5.2r3.2
ivanti connect_secure 9.0
pulsesecure pulse_connect_secure 8.2r4.1
pulsesecure pulse_policy_secure 5.3r1.1
pulsesecure pulse_policy_secure 5.3r7.0
pulsesecure pulse_policy_secure 9.0r3
pulsesecure pulse_policy_secure 5.1r9.0
pulsesecure pulse_policy_secure 5.1r11.1
pulsesecure pulse_policy_secure 5.2r11.0
pulsesecure pulse_connect_secure 8.2r1.0
pulsesecure pulse_connect_secure 8.2r5.1
pulsesecure pulse_connect_secure 8.3
pulsesecure pulse_policy_secure 5.2r9.1
pulsesecure pulse_policy_secure 5.3r5.2
pulsesecure pulse_connect_secure 8.2rx
pulsesecure pulse_policy_secure 5.1r9.1
pulsesecure pulse_policy_secure 5.1r2.0
pulsesecure pulse_policy_secure 5.1r14.0
ivanti connect_secure 8.1
pulsesecure pulse_policy_secure 5.4r2.1
pulsesecure pulse_policy_secure 9.0r2.1
pulsesecure pulse_connect_secure 8.2r1.1
pulsesecure pulse_policy_secure 5.3r4.0
pulsesecure pulse_policy_secure 5.2r10.0
pulsesecure pulse_connect_secure 8.2r3.0
pulsesecure pulse_connect_secure 8.3rx
pulsesecure pulse_policy_secure 5.1r8.0
pulsesecure pulse_connect_secure 8.2r2.0
pulsesecure pulse_policy_secure 5.4rx
pulsesecure pulse_policy_secure 9.0r1
pulsesecure pulse_policy_secure 5.3r10.
pulsesecure pulse_policy_secure 5.4r6.1
pulsesecure pulse_connect_secure 8.2r7.0
pulsesecure pulse_policy_secure 9.0r2
pulsesecure pulse_connect_secure 8.2r6.0
pulsesecure pulse_policy_secure 9.0r3.1
pulsesecure pulse_policy_secure 5.2r4.0
pulsesecure pulse_policy_secure 5.1r5.0
ivanti policy_secure 9.0
pulsesecure pulse_connect_secure 9.0r1
ivanti connect_secure 8.2
pulsesecure pulse_policy_secure 5.1r12.0
pulsesecure pulse_policy_secure 5.3r5.1
pulsesecure pulse_policy_secure 5.3r3.1
pulsesecure pulse_connect_secure 9.0rx
pulsesecure pulse_policy_secure 5.2r7.0
pulsesecure pulse_policy_secure 5.3r8.0
pulsesecure pulse_policy_secure 5.1r13.0
pulsesecure pulse_policy_secure 5.2r5.0
pulsesecure pulse_policy_secure 5.2r7.1
pulsesecure pulse_policy_secure 5.4r2
pulsesecure pulse_policy_secure 5.1r6.0
pulsesecure pulse_policy_secure 5.3r6.0
pulsesecure pulse_policy_secure 5.3r11.0
pulsesecure pulse_policy_secure 5.4r6
pulsesecure pulse_policy_secure 5.1r3.2
pulsesecure pulse_policy_secure 5.3r8.1
pulsesecure pulse_policy_secure 5.1r12.1
pulsesecure pulse_policy_secure 5.1r4.0
ivanti connect_secure 8.3
pulsesecure pulse_policy_secure 5.3r8.2
pulsesecure pulse_connect_secure 8.2r5.0
pulsesecure pulse_connect_secure 8.2r4.0
pulsesecure pulse_policy_secure 5.2r6.0
pulsesecure pulse_policy_secure 5.4r4
pulsesecure pulse_connect_secure 9.0r2
pulsesecure pulse_policy_secure 5.1r3.0
pulsesecure pulse_connect_secure 8.2r7.1
pulsesecure pulse_policy_secure 5.4r5.2
pulsesecure pulse_policy_secure 5.2r2.0
pulsesecure pulse_policy_secure 5.1r10.0
pulsesecure pulse_policy_secure 5.2rx
pulsesecure pulse_policy_secure 5.3r9.0
pulsesecure pulse_policy_secure 5.1r1.0
pulsesecure pulse_connect_secure 9.0r3.2
pulsesecure pulse_policy_secure 5.2r8.0
pulsesecure pulse_policy_secure 9.0rx
pulsesecure pulse_policy_secure 5.2r3.0
pulsesecure pulse_policy_secure 5.3r3.0
pulsesecure pulse_policy_secure 5.3r12.0
pulsesecure pulse_policy_secure 5.4r5
pulsesecure pulse_connect_secure 8.1
pulsesecure pulse_policy_secure 5.3r2.0
pulsesecure pulse_policy_secure 5.1r1.1
pulsesecure pulse_connect_secure 9.0r3
pulsesecure pulse_policy_secure 5.1r11.0
pulsesecure pulse_policy_secure 5.2r9.0
pulsesecure pulse_connect_secure 9.0r3.1
pulsesecure pulse_policy_secure 5.1r2.1
pulsesecure pulse_policy_secure 5.4r7
pulsesecure pulse_connect_secure 8.2r3.1
pulsesecure pulse_connect_secure 9.0r2.1
pulsesecure pulse_policy_secure 5.3r4.1
pulsesecure pulse_policy_secure 5.1r7.0
pulsesecure pulse_policy_secure 5.3rx
CVE-2019-11540 HIGH

In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4 and 8.3RX before 8.3R7.1 and Pulse Policy Secure version 9.0RX before 9.0R3.2 and 5.4RX before 5.4R7.1, an unauthenticated, remote attacker can conduct a session hijacking attack.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
pulsesecure pulse_policy_secure 5.4r3
pulsesecure pulse_connect_secure 9.0rx
pulsesecure pulse_policy_secure 5.4r1
pulsesecure pulse_policy_secure 5.4r2
pulsesecure pulse_connect_secure 8.3rx
pulsesecure pulse_policy_secure 5.4r5.2
pulsesecure pulse_policy_secure 9.0r3
pulsesecure pulse_policy_secure 5.4rx
pulsesecure pulse_connect_secure 9.0r3.2
pulsesecure pulse_policy_secure 9.0rx
pulsesecure pulse_policy_secure 9.0r1
pulsesecure pulse_policy_secure 5.4r5
pulsesecure pulse_connect_secure 8.3
pulsesecure pulse_connect_secure 9.0r3
pulsesecure pulse_policy_secure 5.4r6.1
pulsesecure pulse_policy_secure 5.4r6
pulsesecure pulse_policy_secure 9.0r2
pulsesecure pulse_connect_secure 9.0r3.1
pulsesecure pulse_policy_secure 5.4r7
pulsesecure pulse_policy_secure 9.0r3.1
ivanti connect_secure 8.3
pulsesecure pulse_connect_secure 9.0r2.1
pulsesecure pulse_policy_secure 5.4r2.1
pulsesecure pulse_policy_secure 9.0r2.1
pulsesecure pulse_policy_secure 5.4r4
pulsesecure pulse_connect_secure 9.0r1
pulsesecure pulse_connect_secure 9.0r2
CVE-2019-11541 MEDIUM

In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, and 8.2RX before 8.2R12.1, users using SAML authentication with the Reuse Existing NC (Pulse) Session option may see authentication leaks.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
pulsesecure pulse_connect_secure 8.2
pulsesecure pulse_connect_secure 9.0rx
pulsesecure pulse_connect_secure 8.2r3.0
pulsesecure pulse_connect_secure 8.2r7.1
pulsesecure pulse_connect_secure 8.3rx
pulsesecure pulse_connect_secure 8.2r4.1
pulsesecure pulse_connect_secure 8.2r2.0
pulsesecure pulse_connect_secure 9.0r3.2
pulsesecure pulse_connect_secure 8.2r1.0
pulsesecure pulse_connect_secure 8.2r5.1
pulsesecure pulse_connect_secure 8.3
pulsesecure pulse_connect_secure 9.0r3
pulsesecure pulse_connect_secure 8.2r7.0
pulsesecure pulse_connect_secure 9.0r3.1
pulsesecure pulse_connect_secure 8.2rx
pulsesecure pulse_connect_secure 8.2r6.0
ivanti connect_secure 8.3
pulsesecure pulse_connect_secure 8.2r3.1
pulsesecure pulse_connect_secure 9.0r2.1
pulsesecure pulse_connect_secure 8.2r5.0
pulsesecure pulse_connect_secure 8.2r4.0
pulsesecure pulse_connect_secure 8.2r1.1
pulsesecure pulse_connect_secure 9.0r1
pulsesecure pulse_connect_secure 9.0r2
ivanti connect_secure 8.2
CVE-2019-11542 MEDIUM

In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1RX before 8.1R15.1 and Pulse Policy Secure version 9.0RX before 9.0R3.2, 5.4RX before 5.4R7.1, 5.3RX before 5.3R12.1, 5.2RX before 5.2R12.1, and 5.1RX before 5.1R15.1, an authenticated attacker (via the admin web interface) can send a specially crafted message resulting in a stack buffer overflow.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 7.2 HIGH CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H 1.2 5.9

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-787,

Products Affected

Vendor Product Version
pulsesecure pulse_policy_secure 5.2r1.0
pulsesecure pulse_connect_secure 8.1r1.0
pulsesecure pulse_policy_secure 5.4r3
pulsesecure pulse_policy_secure 5.3r1.0
pulsesecure pulse_connect_secure 8.2
pulsesecure pulse_policy_secure 5.4r1
pulsesecure pulse_policy_secure 5.3r5.0
pulsesecure pulse_policy_secure 5.2r3.2
pulsesecure pulse_connect_secure 8.2r4.1
pulsesecure pulse_policy_secure 5.3r1.1
pulsesecure pulse_policy_secure 5.3r7.0
pulsesecure pulse_policy_secure 9.0r3
pulsesecure pulse_policy_secure 5.1r9.0
pulsesecure pulse_policy_secure 5.1r11.1
pulsesecure pulse_policy_secure 5.2r11.0
pulsesecure pulse_connect_secure 8.2r1.0
pulsesecure pulse_connect_secure 8.2r5.1
pulsesecure pulse_connect_secure 8.3
pulsesecure pulse_policy_secure 5.2r9.1
pulsesecure pulse_policy_secure 5.3r5.2
pulsesecure pulse_connect_secure 8.2rx
pulsesecure pulse_policy_secure 5.1r9.1
pulsesecure pulse_policy_secure 5.1r2.0
pulsesecure pulse_policy_secure 5.1r14.0
ivanti connect_secure 8.1
pulsesecure pulse_policy_secure 5.4r2.1
pulsesecure pulse_policy_secure 9.0r2.1
pulsesecure pulse_connect_secure 8.2r1.1
pulsesecure pulse_policy_secure 5.3r4.0
pulsesecure pulse_policy_secure 5.2r10.0
pulsesecure pulse_connect_secure 8.2r3.0
pulsesecure pulse_connect_secure 8.3rx
pulsesecure pulse_policy_secure 5.1r8.0
pulsesecure pulse_connect_secure 8.2r2.0
pulsesecure pulse_policy_secure 5.4rx
pulsesecure pulse_policy_secure 9.0r1
pulsesecure pulse_policy_secure 5.3r10.
pulsesecure pulse_policy_secure 5.4r6.1
pulsesecure pulse_connect_secure 8.2r7.0
pulsesecure pulse_policy_secure 9.0r2
pulsesecure pulse_connect_secure 8.2r6.0
pulsesecure pulse_policy_secure 9.0r3.1
pulsesecure pulse_policy_secure 5.2r4.0
pulsesecure pulse_policy_secure 5.1r5.0
pulsesecure pulse_connect_secure 9.0r1
ivanti connect_secure 8.2
pulsesecure pulse_policy_secure 5.1r12.0
pulsesecure pulse_policy_secure 5.3r5.1
pulsesecure pulse_policy_secure 5.3r3.1
pulsesecure pulse_connect_secure 9.0rx
pulsesecure pulse_policy_secure 5.2r7.0
pulsesecure pulse_policy_secure 5.3r8.0
pulsesecure pulse_policy_secure 5.1r13.0
pulsesecure pulse_policy_secure 5.2r5.0
pulsesecure pulse_policy_secure 5.2r7.1
pulsesecure pulse_policy_secure 5.4r2
pulsesecure pulse_policy_secure 5.1r6.0
pulsesecure pulse_policy_secure 5.3r6.0
pulsesecure pulse_policy_secure 5.3r11.0
pulsesecure pulse_policy_secure 5.4r6
pulsesecure pulse_policy_secure 5.1r3.2
pulsesecure pulse_policy_secure 5.3r8.1
pulsesecure pulse_policy_secure 5.1r12.1
pulsesecure pulse_policy_secure 5.1r4.0
ivanti connect_secure 8.3
pulsesecure pulse_policy_secure 5.3r8.2
pulsesecure pulse_connect_secure 8.2r5.0
pulsesecure pulse_connect_secure 8.2r4.0
pulsesecure pulse_policy_secure 5.2r6.0
pulsesecure pulse_policy_secure 5.4r4
pulsesecure pulse_connect_secure 9.0r2
pulsesecure pulse_policy_secure 5.1r3.0
pulsesecure pulse_connect_secure 8.2r7.1
pulsesecure pulse_policy_secure 5.4r5.2
pulsesecure pulse_policy_secure 5.2r2.0
pulsesecure pulse_policy_secure 5.1r10.0
pulsesecure pulse_policy_secure 5.2rx
pulsesecure pulse_policy_secure 5.3r9.0
pulsesecure pulse_policy_secure 5.1r1.0
pulsesecure pulse_connect_secure 9.0r3.2
pulsesecure pulse_policy_secure 5.2r8.0
pulsesecure pulse_policy_secure 9.0rx
pulsesecure pulse_policy_secure 5.2r3.0
pulsesecure pulse_policy_secure 5.3r3.0
pulsesecure pulse_policy_secure 5.3r12.0
pulsesecure pulse_policy_secure 5.4r5
pulsesecure pulse_connect_secure 8.1
pulsesecure pulse_policy_secure 5.3r2.0
pulsesecure pulse_policy_secure 5.1r1.1
pulsesecure pulse_connect_secure 9.0r3
pulsesecure pulse_policy_secure 5.1r11.0
pulsesecure pulse_policy_secure 5.2r9.0
pulsesecure pulse_connect_secure 9.0r3.1
pulsesecure pulse_policy_secure 5.1r2.1
pulsesecure pulse_policy_secure 5.4r7
pulsesecure pulse_connect_secure 8.2r3.1
pulsesecure pulse_connect_secure 9.0r2.1
pulsesecure pulse_policy_secure 5.3r4.1
pulsesecure pulse_policy_secure 5.1r7.0
pulsesecure pulse_policy_secure 5.3rx
CVE-2019-11543 MEDIUM

XSS exists in the admin web console in Pulse Secure Pulse Connect Secure (PCS) 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, and 8.1RX before 8.1R15.1 and Pulse Policy Secure 9.0RX before 9.0R3.2, 5.4RX before 5.4R7.1, and 5.2RX before 5.2R12.1.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 6.1 MEDIUM CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N 2.8 2.7

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
pulsesecure pulse_policy_secure 5.2r1.0
pulsesecure pulse_connect_secure 8.1r1.0
pulsesecure pulse_policy_secure 5.4r3
pulsesecure pulse_connect_secure 9.0rx
pulsesecure pulse_policy_secure 5.2r7.0
pulsesecure pulse_policy_secure 5.4r1
pulsesecure pulse_policy_secure 5.2r5.0
pulsesecure pulse_policy_secure 5.2r7.1
pulsesecure pulse_policy_secure 5.2r10.0
pulsesecure pulse_policy_secure 5.4r2
pulsesecure pulse_connect_secure 8.3rx
pulsesecure pulse_policy_secure 5.2r3.2
pulsesecure pulse_policy_secure 5.4r5.2
pulsesecure pulse_policy_secure 5.2r2.0
pulsesecure pulse_policy_secure 5.2rx
pulsesecure pulse_policy_secure 9.0r3
pulsesecure pulse_policy_secure 5.4rx
pulsesecure pulse_policy_secure 5.2r11.0
pulsesecure pulse_connect_secure 9.0r3.2
pulsesecure pulse_policy_secure 5.2r8.0
pulsesecure pulse_policy_secure 9.0rx
pulsesecure pulse_policy_secure 5.2r3.0
pulsesecure pulse_policy_secure 9.0r1
pulsesecure pulse_policy_secure 5.4r5
pulsesecure pulse_connect_secure 8.1
pulsesecure pulse_connect_secure 8.3
pulsesecure pulse_policy_secure 5.2r9.1
pulsesecure pulse_connect_secure 9.0r3
pulsesecure pulse_policy_secure 5.4r6.1
pulsesecure pulse_policy_secure 5.4r6
pulsesecure pulse_policy_secure 9.0r2
pulsesecure pulse_policy_secure 5.2r9.0
pulsesecure pulse_connect_secure 9.0r3.1
pulsesecure pulse_policy_secure 5.4r7
pulsesecure pulse_policy_secure 9.0r3.1
ivanti connect_secure 8.3
pulsesecure pulse_connect_secure 9.0r2.1
ivanti connect_secure 8.1
pulsesecure pulse_policy_secure 5.4r2.1
pulsesecure pulse_policy_secure 5.2r4.0
pulsesecure pulse_policy_secure 9.0r2.1
pulsesecure pulse_policy_secure 5.2r6.0
pulsesecure pulse_policy_secure 5.4r4
pulsesecure pulse_connect_secure 8.1rx
pulsesecure pulse_connect_secure 9.0r1
pulsesecure pulse_connect_secure 9.0r2
CVE-2020-11580 MEDIUM

An issue was discovered in Pulse Secure Pulse Connect Secure (PCS) through 2020-04-06. The applet in tncc.jar, executed on macOS, Linux, and Solaris clients when a Host Checker policy is enforced, accepts an arbitrary SSL certificate.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 9.1 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N 3.9 5.2

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-295,

Products Affected

Vendor Product Version
pulsesecure pulse_policy_secure *
pulsesecure pulse_connect_secure *
CVE-2020-11581 HIGH

An issue was discovered in Pulse Secure Pulse Connect Secure (PCS) through 2020-04-06. The applet in tncc.jar, executed on macOS, Linux, and Solaris clients when a Host Checker policy is enforced, allows a man-in-the-middle attacker to perform OS command injection attacks (against a client) via shell metacharacters to the doCustomRemediateInstructions method, because Runtime.getRuntime().exec() is used.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 8.1 HIGH CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H 2.2 5.9

CVSS 2.0

Severity: HIGH

Problem Type: CWE-78,

Products Affected

Vendor Product Version
pulsesecure pulse_policy_secure -
pulsesecure pulse_connect_secure *
CVE-2020-11582 LOW

An issue was discovered in Pulse Secure Pulse Connect Secure (PCS) through 2020-04-06. The applet in tncc.jar, executed on macOS, Linux, and Solaris clients when a Host Checker policy is enforced, launches a TCP server that accepts local connections on a random port. This can be reached by local HTTP clients, because up to 25 invalid lines are ignored, and because DNS rebinding can occur. (This server accepts, for example, a setcookie command that might be relevant to CVE-2020-11581 exploitation.)

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 8.8 HIGH CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 2.8 5.9

CVSS 2.0

Severity: LOW

Problem Type: CWE-668,

Products Affected

Vendor Product Version
pulsesecure pulse_policy_secure -
pulsesecure pulse_connect_secure *
CVE-2020-12880 LOW

An issue was discovered in Pulse Policy Secure (PPS) and Pulse Connect Secure (PCS) Virtual Appliance before 9.1R8. By manipulating a certain kernel boot parameter, it can be tricked into dropping into a root shell in a pre-install phase where the entire source code of the appliance is available and can be retrieved. (The source code is otherwise inaccessible because the appliance has its hard disks encrypted, and no root shell is available during normal operation.)

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 5.5 MEDIUM CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N 1.8 3.6

CVSS 2.0

Severity: LOW

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
pulsesecure pulse_policy_secure *
ivanti connect_secure 9.1
ivanti policy_secure 9.1
pulsesecure pulse_connect_secure 9.1
pulsesecure pulse_connect_secure *
CVE-2020-13162 MEDIUM

A time-of-check time-of-use vulnerability in PulseSecureService.exe in Pulse Secure Client versions prior to 9.1.6 down to 5.3 R70 for Windows (which runs as NT AUTHORITY/SYSTEM) allows unprivileged users to run a Microsoft Installer executable with elevated privileges.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 7.0 HIGH CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H 1.0 5.9

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-367,CWE-367,

Products Affected

Vendor Product Version
pulsesecure pulse_secure_installer_service 9.1
pulsesecure pulse_secure_desktop_client 5.3
pulsesecure pulse_secure_installer_service 8.3
pulsesecure pulse_secure_desktop_client 9.0
pulsesecure pulse_secure_desktop_client 9.1
CVE-2020-15352 MEDIUM

An XML external entity (XXE) vulnerability in Pulse Connect Secure (PCS) before 9.1R9 and Pulse Policy Secure (PPS) before 9.1R9 allows remote authenticated admins to conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML request.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 7.2 HIGH CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H 1.2 5.9

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-611,

Products Affected

Vendor Product Version
pulsesecure pulse_policy_secure *
ivanti connect_secure 9.1
ivanti policy_secure 9.1
pulsesecure pulse_connect_secure 9.1
pulsesecure pulse_connect_secure *
CVE-2020-15408 MEDIUM

An issue was discovered in Pulse Secure Pulse Connect Secure before 9.1R8. An authenticated attacker can access the admin page console via the end-user web interface because of a rewrite.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 4.6 MEDIUM CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N 2.1 2.5
cve@mitre.org 3.7 LOW CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N 1.2 2.5

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
pulsesecure pulse_connect_secure *
pulsesecure pulse_secure_desktop_client 9.1
CVE-2020-8204 MEDIUM

A cross site scripting (XSS) vulnerability exists in Pulse Connect Secure <9.1R5 on the PSAL Page.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 6.1 MEDIUM CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N 2.8 2.7

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,CWE-79,

Products Affected

Vendor Product Version
pulsesecure pulse_policy_secure *
ivanti connect_secure 9.1
ivanti policy_secure 9.1
pulsesecure pulse_connect_secure 9.1
pulsesecure pulse_connect_secure *
CVE-2020-8206 MEDIUM

An improper authentication vulnerability exists in Pulse Connect Secure <9.1RB that allows an attacker with a users primary credentials to bypass the Google TOTP.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 8.1 HIGH CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H 2.2 5.9

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-287,CWE-287,

Products Affected

Vendor Product Version
pulsesecure pulse_policy_secure *
ivanti connect_secure 9.1
ivanti policy_secure 9.1
pulsesecure pulse_connect_secure 9.1
pulsesecure pulse_connect_secure *
CVE-2020-8216 MEDIUM

An information disclosure vulnerability in meeting of Pulse Connect Secure <9.1R8 allowed an authenticated end-users to find meeting details, if they know the Meeting ID.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 4.3 MEDIUM CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N 2.8 1.4

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,NVD-CWE-noinfo,

Products Affected

Vendor Product Version
pulsesecure pulse_policy_secure *
ivanti connect_secure 9.1
ivanti policy_secure 9.1
pulsesecure pulse_connect_secure 9.1
pulsesecure pulse_connect_secure *
CVE-2020-8217 LOW

A cross site scripting (XSS) vulnerability in Pulse Connect Secure <9.1R8 allowed attackers to exploit in the URL used for Citrix ICA.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 5.4 MEDIUM CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N 2.3 2.7

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,CWE-79,

Products Affected

Vendor Product Version
pulsesecure pulse_policy_secure *
ivanti connect_secure 9.1
ivanti policy_secure 9.1
pulsesecure pulse_connect_secure 9.1
pulsesecure pulse_connect_secure *
CVE-2020-8218 MEDIUM

A code injection vulnerability exists in Pulse Connect Secure <9.1R8 that allows an attacker to crafted a URI to perform an arbitrary code execution via the admin web interface.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-94,CWE-94,

Products Affected

Vendor Product Version
ivanti connect_secure *
pulsesecure pulse_policy_secure *
pulsesecure pulse_policy_secure 9.1
ivanti connect_secure 9.1
ivanti policy_secure 9.1
pulsesecure pulse_connect_secure 9.1
pulsesecure pulse_connect_secure *
CVE-2020-8219 MEDIUM

An insufficient permission check vulnerability exists in Pulse Connect Secure <9.1R8 that allows an attacker to change the password of a full administrator.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 7.2 HIGH CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H 1.2 5.9

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-280,CWE-276,

Products Affected

Vendor Product Version
pulsesecure pulse_policy_secure *
ivanti connect_secure 9.1
ivanti policy_secure 9.1
pulsesecure pulse_connect_secure 9.1
pulsesecure pulse_connect_secure *
CVE-2020-8220 MEDIUM

A denial of service vulnerability exists in Pulse Connect Secure <9.1R8 that allows an authenticated attacker to perform command injection via the administrator web which can cause DOS.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 6.5 MEDIUM CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H 1.2 5.2

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-400,CWE-400,

Products Affected

Vendor Product Version
pulsesecure pulse_policy_secure *
ivanti connect_secure 9.1
ivanti policy_secure 9.1
pulsesecure pulse_connect_secure 9.1
pulsesecure pulse_connect_secure *
CVE-2020-8221 MEDIUM

A path traversal vulnerability exists in Pulse Connect Secure <9.1R8 which allows an authenticated attacker to read arbitrary files via the administrator web interface.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 4.9 MEDIUM CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N 1.2 3.6

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-22,CWE-22,

Products Affected

Vendor Product Version
pulsesecure pulse_policy_secure *
ivanti connect_secure 9.1
ivanti policy_secure 9.1
pulsesecure pulse_connect_secure 9.1
pulsesecure pulse_connect_secure *
CVE-2020-8222 MEDIUM

A path traversal vulnerability exists in Pulse Connect Secure <9.1R8 that allowed an authenticated attacker via the administrator web interface to perform an arbitrary file reading vulnerability through Meeting.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 6.8 MEDIUM CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N 2.3 4.0

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-22,CWE-22,

Products Affected

Vendor Product Version
pulsesecure pulse_policy_secure *
ivanti connect_secure 9.1
ivanti policy_secure 9.1
pulsesecure pulse_connect_secure 9.1
pulsesecure pulse_connect_secure *
CVE-2020-8238 MEDIUM

A vulnerability in the authenticated user web interface of Pulse Connect Secure and Pulse Policy Secure < 9.1R8.2 could allow attackers to conduct Cross-Site Scripting (XSS).

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,CWE-79,

Products Affected

Vendor Product Version
pulsesecure pulse_policy_secure *
pulsesecure pulse_policy_secure 9.1
ivanti connect_secure 9.1
ivanti policy_secure 9.1
pulsesecure pulse_connect_secure 9.1
pulsesecure pulse_connect_secure *
CVE-2020-8239 HIGH

A vulnerability in the Pulse Secure Desktop Client < 9.1R9 is vulnerable to the client registry privilege escalation attack. This fix also requires Server Side Upgrade due to Standalone Host Checker Client (Windows) and Windows PDC.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 3.9 5.9

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
pulsesecure pulse_secure_desktop_client *
pulsesecure pulse_secure_desktop_client 9.1
CVE-2020-8240 MEDIUM

A vulnerability in the Pulse Secure Desktop Client < 9.1R9 allows a restricted user on an endpoint machine can use system-level privileges if the Embedded Browser is configured with Credential Provider. This vulnerability only affects Windows PDC if the Embedded Browser is configured with the Credential Provider.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H 1.8 5.9

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
pulsesecure pulse_secure_desktop_client *
pulsesecure pulse_secure_desktop_client 9.1
CVE-2020-8241 MEDIUM

A vulnerability in the Pulse Secure Desktop Client < 9.1R9 could allow the attacker to perform a MITM Attack if end users are convinced to connect to a malicious server.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 7.5 HIGH CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H 1.6 5.9

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
pulsesecure pulse_secure_desktop_client *
pulsesecure pulse_secure_desktop_client 9.1
CVE-2020-8243 MEDIUM

A vulnerability in the Pulse Connect Secure < 9.1R8.2 admin web interface could allow an authenticated attacker to upload custom template to perform an arbitrary code execution.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 7.2 HIGH CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H 1.2 5.9

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-94,CWE-94,

Products Affected

Vendor Product Version
ivanti connect_secure *
pulsesecure pulse_policy_secure *
ivanti connect_secure 9.1
ivanti policy_secure 9.1
pulsesecure pulse_connect_secure 9.1
pulsesecure pulse_connect_secure *
ivanti policy_secure *
CVE-2020-8248 MEDIUM

A vulnerability in the Pulse Secure Desktop Client (Linux) < 9.1R9 could allow local attackers to escalate privilege.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H 1.8 5.9

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
pulsesecure pulse_secure_desktop_client *
pulsesecure pulse_secure_desktop_client 9.1
CVE-2020-8249 MEDIUM

A vulnerability in the Pulse Secure Desktop Client (Linux) < 9.1R9 could allow local attackers to perform buffer overflow.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H 1.8 5.9

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-120,CWE-120,

Products Affected

Vendor Product Version
pulsesecure pulse_secure_desktop_client *
pulsesecure pulse_secure_desktop_client 9.1
CVE-2020-8250 MEDIUM

A vulnerability in the Pulse Secure Desktop Client (Linux) < 9.1R9 could allow local attackers to escalate privilege.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H 1.8 5.9

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
pulsesecure pulse_secure_desktop_client *
pulsesecure pulse_secure_desktop_client 9.1
CVE-2020-8254 MEDIUM

A vulnerability in the Pulse Secure Desktop Client < 9.1R9 has Remote Code Execution (RCE) if users can be convinced to connect to a malicious server. This vulnerability only affects Windows PDC.To improve the security of connections between Pulse clients and Pulse Connect Secure, see below recommendation(s):Disable Dynamic certificate trust for PDC.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 8.8 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H 2.8 5.9

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-23,CWE-22,

Products Affected

Vendor Product Version
pulsesecure pulse_secure_desktop_client *
pulsesecure pulse_secure_desktop_client 9.1
CVE-2020-8255 MEDIUM

A vulnerability in the Pulse Connect Secure < 9.1R9 admin web interface could allow an authenticated attacker to perform an arbitrary file reading vulnerability is fixed using encrypted URL blacklisting that prevents these messages.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 4.9 MEDIUM CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N 1.2 3.6

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,NVD-CWE-noinfo,

Products Affected

Vendor Product Version
pulsesecure pulse_secure_desktop_client *
pulsesecure pulse_secure_desktop_client 9.1
CVE-2020-8256 MEDIUM

A vulnerability in the Pulse Connect Secure < 9.1R8.2 admin web interface could allow an authenticated attacker to gain arbitrary file reading access through Pulse Collaboration via XML External Entity (XXE) vulnerability.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-611,CWE-611,

Products Affected

Vendor Product Version
ivanti connect_secure 9.1
pulsesecure pulse_connect_secure 9.1
pulsesecure pulse_connect_secure *
CVE-2020-8260 MEDIUM

A vulnerability in the Pulse Connect Secure < 9.1R9 admin web interface could allow an authenticated attacker to perform an arbitrary code execution using uncontrolled gzip extraction.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 7.2 HIGH CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H 1.2 5.9

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-434,CWE-434,

Products Affected

Vendor Product Version
ivanti connect_secure *
pulsesecure pulse_secure_desktop_client *
ivanti connect_secure 9.1
pulsesecure pulse_secure_desktop_client 9.1
CVE-2020-8261 MEDIUM

A vulnerability in the Pulse Connect Secure / Pulse Policy Secure < 9.1R9 is vulnerable to arbitrary cookie injection.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 4.3 MEDIUM CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N 2.8 1.4

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-120,CWE-120,

Products Affected

Vendor Product Version
pulsesecure pulse_policy_secure *
ivanti connect_secure 9.1
ivanti policy_secure 9.1
pulsesecure pulse_connect_secure 9.1
pulsesecure pulse_connect_secure *
CVE-2020-8262 MEDIUM

A vulnerability in the Pulse Connect Secure / Pulse Policy Secure below 9.1R9 could allow attackers to conduct Cross-Site Scripting (XSS) and Open Redirection for authenticated user web interface.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 6.1 MEDIUM CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N 2.8 2.7

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,CWE-79,

Products Affected

Vendor Product Version
pulsesecure pulse_policy_secure *
ivanti connect_secure 9.1
ivanti policy_secure 9.1
pulsesecure pulse_connect_secure 9.1
pulsesecure pulse_connect_secure *
CVE-2020-8263 LOW

A vulnerability in the authenticated user web interface of Pulse Connect Secure < 9.1R9 could allow attackers to conduct Cross-Site Scripting (XSS) through the CGI file.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 5.4 MEDIUM CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N 2.3 2.7

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,CWE-79,

Products Affected

Vendor Product Version
pulsesecure pulse_secure_desktop_client *
pulsesecure pulse_secure_desktop_client 9.1
CVE-2020-8956 LOW

Pulse Secure Desktop Client 9.0Rx before 9.0R5 and 9.1Rx before 9.1R4 on Windows reveals users' passwords if Save Settings is enabled.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 3.3 LOW CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N 1.8 1.4

CVSS 2.0

Severity: LOW

Problem Type: CWE-521,

Products Affected

Vendor Product Version
pulsesecure pulse_secure_desktop 9.1r3.0
pulsesecure pulse_secure_desktop 9.0r3.0
pulsesecure pulse_secure_desktop 9.0r3.1
pulsesecure pulse_secure_desktop 9.1r3.1
pulsesecure pulse_secure_desktop 9.0r4.0
pulsesecure pulse_secure_desktop 9.0r2.0
pulsesecure pulse_secure_desktop 9.0r4.1
pulsesecure pulse_secure_desktop 9.1r1.0
pulsesecure pulse_secure_desktop 9.0r1.0
pulsesecure pulse_secure_desktop 9.1r2.0
pulsesecure pulse_secure_desktop 9.0r2.1
CVE-2021-22887 LOW

A vulnerability in the BIOS of Pulse Secure (PSA-Series Hardware) models PSA5000 and PSA7000 could allow an attacker to compromise BIOS firmware. This vulnerability can be exploited only as part of an attack chain. Before an attacker can compromise the BIOS, they must exploit the device.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 2.3 LOW CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N 0.8 1.4

CVSS 2.0

Severity: LOW

Problem Type: CWE-506,NVD-CWE-Other,

Products Affected

Vendor Product Version
supermicro x10sll-f_firmware *
supermicro x10slm+ln4f_firmware *
supermicro x10sll-sf_firmware *
pulsesecure psa-7000_firmware -
supermicro x10sl7-f_firmware *
supermicro x10sll+f_firmware *
supermicro x10slm-f_firmware *
pulsesecure psa-5000_firmware -
supermicro x10sll-s_firmware *
supermicro x10sla-f_firmware *
supermicro x10slm+-f_firmware *
supermicro x10slh-f_firmware *
CVE-2021-22893 HIGH

Pulse Connect Secure 9.0R3/9.1R1 and higher is vulnerable to an authentication bypass vulnerability exposed by the Windows File Share Browser and Pulse Secure Collaboration features of Pulse Connect Secure that can allow an unauthenticated user to perform remote arbitrary code execution on the Pulse Connect Secure gateway. This vulnerability has been exploited in the wild.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 10.0 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H 3.9 6.0

CVSS 2.0

Severity: HIGH

Problem Type: CWE-287,CWE-416,

Products Affected

Vendor Product Version
ivanti connect_secure 9.1
pulsesecure pulse_connect_secure 9.1
ivanti connect_secure 9.0
CVE-2021-22894 HIGH

A buffer overflow vulnerability exists in Pulse Connect Secure before 9.1R11.4 allows a remote authenticated attacker to execute arbitrary code as the root user via maliciously crafted meeting room.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 8.8 HIGH CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H 2.8 5.9

CVSS 2.0

Severity: HIGH

Problem Type: CWE-94,CWE-119,

Products Affected

Vendor Product Version
ivanti connect_secure 9.1
pulsesecure pulse_connect_secure 9.1
pulsesecure pulse_connect_secure 9.0
pulsesecure pulse_connect_secure *
ivanti connect_secure 9.0
CVE-2021-22899 MEDIUM

A command injection vulnerability exists in Pulse Connect Secure before 9.1R11.4 allows a remote authenticated attacker to perform remote code execution via Windows Resource Profiles Feature

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 8.8 HIGH CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H 2.8 5.9

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-77,CWE-77,

Products Affected

Vendor Product Version
pulsesecure pulse_connect_secure 9.0rx
ivanti connect_secure 9.1
pulsesecure pulse_connect_secure 9.1
pulsesecure pulse_connect_secure 9.0
pulsesecure pulse_connect_secure *
ivanti connect_secure 9.0
CVE-2021-22900 MEDIUM

A vulnerability allowed multiple unrestricted uploads in Pulse Connect Secure before 9.1R11.4 that could lead to an authenticated administrator to perform a file write via a maliciously crafted archive upload in the administrator web interface.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 7.2 HIGH CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H 1.2 5.9

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-94,CWE-669,

Products Affected

Vendor Product Version
ivanti connect_secure 9.1
pulsesecure pulse_connect_secure 9.1
pulsesecure pulse_connect_secure 9.0
pulsesecure pulse_connect_secure *
ivanti connect_secure 9.0
CVE-2021-22908 HIGH

A buffer overflow vulnerability exists in Windows File Resource Profiles in 9.X allows a remote authenticated user with privileges to browse SMB shares to execute arbitrary code as the root user. As of version 9.1R3, this permission is not enabled by default.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 8.8 HIGH CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H 2.8 5.9

CVSS 2.0

Severity: HIGH

Problem Type: CWE-120,CWE-120,

Products Affected

Vendor Product Version
pulsesecure pulse_connect_secure 9.0rx
ivanti connect_secure 9.1
pulsesecure pulse_connect_secure 9.1
pulsesecure pulse_connect_secure 9.0
ivanti connect_secure 9.0
CVE-2021-22933 MEDIUM

A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator to perform an arbitrary file delete via a maliciously crafted web request.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 6.5 MEDIUM CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H 1.2 5.2

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-22,CWE-22,

Products Affected

Vendor Product Version
ivanti connect_secure 9.1
pulsesecure pulse_connect_secure *
CVE-2021-22934 MEDIUM

A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator or compromised Pulse Connect Secure device in a load-balanced configuration to perform a buffer overflow via a malicious crafted web request.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 7.2 HIGH CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H 1.2 5.9

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-120,CWE-120,

Products Affected

Vendor Product Version
ivanti connect_secure 9.1
pulsesecure pulse_connect_secure *
CVE-2021-22935 MEDIUM

A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator to perform command injection via an unsanitized web parameter.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 7.2 HIGH CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H 1.2 5.9

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-77,CWE-77,

Products Affected

Vendor Product Version
ivanti connect_secure 9.1
pulsesecure pulse_connect_secure *
CVE-2021-22936 MEDIUM

A vulnerability in Pulse Connect Secure before 9.1R12 could allow a threat actor to perform a cross-site script attack against an authenticated administrator via an unsanitized web parameter.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 6.1 MEDIUM CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N 2.8 2.7

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,CWE-79,

Products Affected

Vendor Product Version
ivanti connect_secure 9.1
pulsesecure pulse_connect_secure *
CVE-2021-22937 MEDIUM

A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator to perform a file write via a maliciously crafted archive uploaded in the administrator web interface.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 7.2 HIGH CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H 1.2 5.9

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-434,CWE-434,

Products Affected

Vendor Product Version
ivanti connect_secure 9.1
pulsesecure pulse_connect_secure *
CVE-2021-22938 MEDIUM

A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator to perform command injection via an unsanitized web parameter in the administrator web console.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 7.2 HIGH CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H 1.2 5.9

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-77,CWE-77,

Products Affected

Vendor Product Version
ivanti connect_secure 9.1
pulsesecure pulse_connect_secure *
CVE-2021-22965 HIGH

A vulnerability in Pulse Connect Secure before 9.1R12.1 could allow an unauthenticated administrator to causes a denial of service when a malformed request is sent to the device.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H 3.9 3.6

CVSS 2.0

Severity: HIGH

Problem Type: CWE-400,CWE-400,

Products Affected

Vendor Product Version
ivanti connect_secure 9.1
pulsesecure pulse_connect_secure *
CVE-2021-31922 MEDIUM

An HTTP Request Smuggling vulnerability in Pulse Secure Virtual Traffic Manager before 21.1 could allow an attacker to smuggle an HTTP request through an HTTP/2 Header. This vulnerability is resolved in 21.1, 20.3R1, 20.2R1, 20.1R2, 19.2R4, and 18.2R3.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N 3.9 3.6

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-444,

Products Affected

Vendor Product Version
pulsesecure virtual_traffic_manager 19.3
pulsesecure virtual_traffic_manager *
pulsesecure virtual_traffic_manager 18.2
pulsesecure virtual_traffic_manager 20.2
pulsesecure virtual_traffic_manager 20.3
pulsesecure virtual_traffic_manager 20.1
pulsesecure virtual_traffic_manager 19.2
CVE-2021-44720

In Ivanti Pulse Secure Pulse Connect Secure (PCS) before 9.1R12, the administrator password is stored in the HTML source code of the "Maintenance > Push Configuration > Targets > Target Name" targets.cgi screen. A read-only administrative user can escalate to a read-write administrative role.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 7.2 HIGH CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H 1.2 5.9

Products Affected

Vendor Product Version
ivanti connect_secure 9.1
pulsesecure pulse_connect_secure *
CVE-2022-21826

Pulse Secure version 9.115 and below may be susceptible to client-side http request smuggling, When the application receives a POST request, it ignores the request's Content-Length header and leaves the POST body on the TCP/TLS socket. This body ends up prefixing the next HTTP request sent down that connection, this means when someone loads website attacker may be able to make browser issue a POST to the application, enabling XSS.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 5.4 MEDIUM CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N 2.3 2.7

Products Affected

Vendor Product Version
ivanti connect_secure 9.1
pulsesecure pulse_connect_secure *
CVE-2022-35254

An unauthenticated attacker can cause a denial-of-service to the following products: Ivanti Connect Secure (ICS) in versions prior to 9.1R14.3, 9.1R15.2, 9.1R16.2, and 22.2R4, Ivanti Policy Secure (IPS) in versions prior to 9.1R17 and 22.3R1, and Ivanti Neurons for Zero-Trust Access in versions prior to 22.3R1.

Products Affected

Vendor Product Version
ivanti connect_secure 22.1
pulsesecure pulse_policy_secure 9.1
ivanti connect_secure 21.12
ivanti neurons_for_zero-trust_access 22.2
ivanti policy_secure 22.1
ivanti connect_secure *
ivanti connect_secure 21.9
ivanti policy_secure 22.2
ivanti connect_secure 9.1
ivanti policy_secure 9.1
pulsesecure pulse_connect_secure 9.1
ivanti connect_secure 22.2
ivanti policy_secure *
CVE-2022-35258

An unauthenticated attacker can cause a denial-of-service to the following products: Ivanti Connect Secure (ICS) in versions prior to 9.1R14.3, 9.1R15.2, 9.1R16.2, and 22.2R4, Ivanti Policy Secure (IPS) in versions prior to 9.1R17 and 22.3R1, and Ivanti Neurons for Zero-Trust Access in versions prior to 22.3R1.

Products Affected

Vendor Product Version
ivanti connect_secure 22.1
pulsesecure pulse_policy_secure 9.1
ivanti connect_secure 21.12
ivanti neurons_for_zero-trust_access 22.2
ivanti policy_secure 22.1
ivanti connect_secure *
ivanti connect_secure 21.9
ivanti policy_secure 22.2
ivanti connect_secure 9.1
ivanti policy_secure 9.1
pulsesecure pulse_connect_secure 9.1
ivanti connect_secure 22.2
ivanti policy_secure *