Pulse Connect Secure Pulse Policy Secure vulnerabilities
5 known vulnerabilities affecting pulse_connect_secure/pulse_policy_secure.
Total CVEs
5
CISA KEV
1
actively exploited
Public exploits
0
Exploited in wild
1
Severity breakdown
HIGH1MEDIUM4
Vulnerabilities
Page 1 of 1
CVE-2020-8260HIGHCVSS 7.2KEVv9.1R92020-10-28
CVE-2020-8260 [HIGH] CWE-434 CVE-2020-8260: A vulnerability in the Pulse Connect Secure < 9.1R9 admin web interface could allow an authenticated
A vulnerability in the Pulse Connect Secure < 9.1R9 admin web interface could allow an authenticated attacker to perform an arbitrary code execution using uncontrolled gzip extraction.
cvelistv5nvd
CVE-2020-8255MEDIUMCVSS 4.9v9.1R92020-10-28
CVE-2020-8255 [MEDIUM] CWE-20 CVE-2020-8255: A vulnerability in the Pulse Connect Secure < 9.1R9 admin web interface could allow an authenticated
A vulnerability in the Pulse Connect Secure < 9.1R9 admin web interface could allow an authenticated attacker to perform an arbitrary file reading vulnerability is fixed using encrypted URL blacklisting that prevents these messages.
cvelistv5nvd
CVE-2020-8263MEDIUMCVSS 5.4v9.1R92020-10-28
CVE-2020-8263 [MEDIUM] CWE-79 CVE-2020-8263: A vulnerability in the authenticated user web interface of Pulse Connect Secure < 9.1R9 could allow
A vulnerability in the authenticated user web interface of Pulse Connect Secure < 9.1R9 could allow attackers to conduct Cross-Site Scripting (XSS) through the CGI file.
cvelistv5nvd
CVE-2020-8261MEDIUMCVSS 4.3v9.1R92020-10-28
CVE-2020-8261 [MEDIUM] CWE-120 CVE-2020-8261: A vulnerability in the Pulse Connect Secure / Pulse Policy Secure < 9.1R9 is vulnerable to arbitrary
A vulnerability in the Pulse Connect Secure / Pulse Policy Secure < 9.1R9 is vulnerable to arbitrary cookie injection.
cvelistv5nvd
CVE-2020-8262MEDIUMCVSS 6.1vFixed in 9.1R92020-10-28
CVE-2020-8262 [MEDIUM] CWE-79 CVE-2020-8262: A vulnerability in the Pulse Connect Secure / Pulse Policy Secure below 9.1R9 could allow attackers
A vulnerability in the Pulse Connect Secure / Pulse Policy Secure below 9.1R9 could allow attackers to conduct Cross-Site Scripting (XSS) and Open Redirection for authenticated user web interface.
cvelistv5nvd