Pulsesecure Pulse Connect Secure vulnerabilities
61 known vulnerabilities affecting pulsesecure/pulse_connect_secure.
Total CVEs
61
CISA KEV
5
actively exploited
Public exploits
0
Exploited in wild
5
Severity breakdown
CRITICAL6HIGH30MEDIUM25
Vulnerabilities
Page 1 of 4
CVE-2022-21826MEDIUMCVSS 5.4fixed in 9.12022-09-30
CVE-2022-21826 [MEDIUM] CWE-444 CVE-2022-21826: Pulse Secure version 9.115 and below may be susceptible to client-side http request smuggling, When
Pulse Secure version 9.115 and below may be susceptible to client-side http request smuggling, When the application receives a POST request, it ignores the request's Content-Length header and leaves the POST body on the TCP/TLS socket. This body ends up prefixing the next HTTP request sent down that connection, this means when someone loads website a
nvd
CVE-2021-44720HIGHCVSS 7.2fixed in 9.12022-08-12
CVE-2021-44720 [HIGH] CWE-798 CVE-2021-44720: In Ivanti Pulse Secure Pulse Connect Secure (PCS) before 9.1R12, the administrator password is store
In Ivanti Pulse Secure Pulse Connect Secure (PCS) before 9.1R12, the administrator password is stored in the HTML source code of the "Maintenance > Push Configuration > Targets > Target Name" targets.cgi screen. A read-only administrative user can escalate to a read-write administrative role.
nvd
CVE-2021-22965HIGHCVSS 7.5fixed in 9.1vFixed in 9.1R12.12021-11-19
CVE-2021-22965 [HIGH] CWE-400 CVE-2021-22965: A vulnerability in Pulse Connect Secure before 9.1R12.1 could allow an unauthenticated administrator
A vulnerability in Pulse Connect Secure before 9.1R12.1 could allow an unauthenticated administrator to causes a denial of service when a malformed request is sent to the device.
cvelistv5nvd
CVE-2021-22934HIGHCVSS 7.2fixed in 9.1vFixed in 9.1R122021-08-16
CVE-2021-22934 [HIGH] CWE-120 CVE-2021-22934: A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator or
A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator or compromised Pulse Connect Secure device in a load-balanced configuration to perform a buffer overflow via a malicious crafted web request.
cvelistv5nvd
CVE-2021-22937HIGHCVSS 7.2fixed in 9.1vFixed in 9.1R122021-08-16
CVE-2021-22937 [HIGH] CWE-434 CVE-2021-22937: A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator to
A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator to perform a file write via a maliciously crafted archive uploaded in the administrator web interface.
cvelistv5nvd
CVE-2021-22938HIGHCVSS 7.2fixed in 9.1vFixed in 9.1R122021-08-16
CVE-2021-22938 [HIGH] CWE-77 CVE-2021-22938: A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator to
A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator to perform command injection via an unsanitized web parameter in the administrator web console.
cvelistv5nvd
CVE-2021-22935HIGHCVSS 7.2fixed in 9.1vFixed in 9.1R122021-08-16
CVE-2021-22935 [HIGH] CWE-77 CVE-2021-22935: A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator to
A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator to perform command injection via an unsanitized web parameter.
cvelistv5nvd
CVE-2021-22936MEDIUMCVSS 6.1fixed in 9.1vFixed in 9.1R122021-08-16
CVE-2021-22936 [MEDIUM] CWE-79 CVE-2021-22936: A vulnerability in Pulse Connect Secure before 9.1R12 could allow a threat actor to perform a cross-
A vulnerability in Pulse Connect Secure before 9.1R12 could allow a threat actor to perform a cross-site script attack against an authenticated administrator via an unsanitized web parameter.
cvelistv5nvd
CVE-2021-22933MEDIUMCVSS 6.5fixed in 9.1vFixed in 9.1R122021-08-16
CVE-2021-22933 [MEDIUM] CWE-22 CVE-2021-22933: A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator to
A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator to perform an arbitrary file delete via a maliciously crafted web request.
cvelistv5nvd
CVE-2021-22908HIGHCVSS 8.8v9.0rxvFixed in 9.1R11.52021-05-27
CVE-2021-22908 [HIGH] CWE-120 CVE-2021-22908: A buffer overflow vulnerability exists in Windows File Resource Profiles in 9.X allows a remote auth
A buffer overflow vulnerability exists in Windows File Resource Profiles in 9.X allows a remote authenticated user with privileges to browse SMB shares to execute arbitrary code as the root user. As of version 9.1R3, this permission is not enabled by default.
cvelistv5nvd
CVE-2021-22900HIGHCVSS 7.2KEV≤ 9.12021-05-27
CVE-2021-22900 [HIGH] CWE-94 CVE-2021-22900: A vulnerability allowed multiple unrestricted uploads in Pulse Connect Secure before 9.1R11.4 that c
A vulnerability allowed multiple unrestricted uploads in Pulse Connect Secure before 9.1R11.4 that could lead to an authenticated administrator to perform a file write via a maliciously crafted archive upload in the administrator web interface.
nvd
CVE-2021-22899HIGHCVSS 8.8KEVvFixed in 9.1R11.42021-05-27
CVE-2021-22899 [HIGH] CWE-77 CVE-2021-22899: A command injection vulnerability exists in Pulse Connect Secure before 9
A command injection vulnerability exists in Pulse Connect Secure before 9.1R11.4 allows a remote authenticated attacker to perform remote code execution via Windows Resource Profiles Feature
cvelistv5
CVE-2021-22894HIGHCVSS 8.8KEVvFixed version 9.1R11.42021-05-27
CVE-2021-22894 [HIGH] CWE-94 CVE-2021-22894: A buffer overflow vulnerability exists in Pulse Connect Secure before 9
A buffer overflow vulnerability exists in Pulse Connect Secure before 9.1R11.4 allows a remote authenticated attacker to execute arbitrary code as the root user via maliciously crafted meeting room.
cvelistv5
CVE-2021-22893CRITICALCVSS 10.0KEVvPCS 9.0R3 or above, PCS 9.1R1 and above2021-04-23
CVE-2021-22893 [CRITICAL] CWE-287 CVE-2021-22893: Pulse Connect Secure 9
Pulse Connect Secure 9.0R3/9.1R1 and higher is vulnerable to an authentication bypass vulnerability exposed by the Windows File Share Browser and Pulse Secure Collaboration features of Pulse Connect Secure that can allow an unauthenticated user to perform remote arbitrary code execution on the Pulse Connect Secure gateway. This vulnerability has been exploited in the wild.
cvelistv5
CVE-2020-8261MEDIUMCVSS 4.3fixed in 9.12020-10-28
CVE-2020-8261 [MEDIUM] CWE-120 CVE-2020-8261: A vulnerability in the Pulse Connect Secure / Pulse Policy Secure < 9.1R9 is vulnerable to arbitrary
A vulnerability in the Pulse Connect Secure / Pulse Policy Secure < 9.1R9 is vulnerable to arbitrary cookie injection.
nvd
CVE-2020-8262MEDIUMCVSS 6.1fixed in 9.12020-10-28
CVE-2020-8262 [MEDIUM] CWE-79 CVE-2020-8262: A vulnerability in the Pulse Connect Secure / Pulse Policy Secure below 9.1R9 could allow attackers
A vulnerability in the Pulse Connect Secure / Pulse Policy Secure below 9.1R9 could allow attackers to conduct Cross-Site Scripting (XSS) and Open Redirection for authenticated user web interface.
nvd
CVE-2020-15352HIGHCVSS 7.2≤ 9.02020-10-27
CVE-2020-15352 [HIGH] CWE-611 CVE-2020-15352: An XML external entity (XXE) vulnerability in Pulse Connect Secure (PCS) before 9.1R9 and Pulse Poli
An XML external entity (XXE) vulnerability in Pulse Connect Secure (PCS) before 9.1R9 and Pulse Policy Secure (PPS) before 9.1R9 allows remote authenticated admins to conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML request.
nvd
CVE-2020-8256MEDIUMCVSS 4.9≤ 9.0vFixed in 9.1R8.22020-09-30
CVE-2020-8256 [MEDIUM] CWE-611 CVE-2020-8256: A vulnerability in the Pulse Connect Secure < 9.1R8.2 admin web interface could allow an authenticat
A vulnerability in the Pulse Connect Secure < 9.1R8.2 admin web interface could allow an authenticated attacker to gain arbitrary file reading access through Pulse Collaboration via XML External Entity (XXE) vulnerability.
cvelistv5nvd
CVE-2020-8238MEDIUMCVSS 6.1≤ 9.02020-09-30
CVE-2020-8238 [MEDIUM] CWE-79 CVE-2020-8238: A vulnerability in the authenticated user web interface of Pulse Connect Secure and Pulse Policy Sec
A vulnerability in the authenticated user web interface of Pulse Connect Secure and Pulse Policy Secure < 9.1R8.2 could allow attackers to conduct Cross-Site Scripting (XSS).
nvd
CVE-2020-8206HIGHCVSS 8.1≤ 9.0vFixed in 9.1R82020-07-30
CVE-2020-8206 [HIGH] CWE-287 CVE-2020-8206: An improper authentication vulnerability exists in Pulse Connect Secure <9.1RB that allows an attack
An improper authentication vulnerability exists in Pulse Connect Secure <9.1RB that allows an attacker with a users primary credentials to bypass the Google TOTP.
cvelistv5nvd
1 / 4Next →