Pulsesecure Pulse Connect Secure vulnerabilities

61 known vulnerabilities affecting pulsesecure/pulse_connect_secure.

Total CVEs
61
CISA KEV
5
actively exploited
Public exploits
0
Exploited in wild
5
Severity breakdown
CRITICAL6HIGH30MEDIUM25

Vulnerabilities

Page 2 of 4
CVE-2020-8219HIGHCVSS 7.2≤ 9.0vFixed in 9.1R82020-07-30
CVE-2020-8219 [HIGH] CWE-280 CVE-2020-8219: An insufficient permission check vulnerability exists in Pulse Connect Secure <9.1R8 that allows an An insufficient permission check vulnerability exists in Pulse Connect Secure <9.1R8 that allows an attacker to change the password of a full administrator.
cvelistv5nvd
CVE-2020-8218HIGHCVSS 7.2KEVvFixed in 9.1R82020-07-30
CVE-2020-8218 [HIGH] CWE-94 CVE-2020-8218: A code injection vulnerability exists in Pulse Connect Secure <9 A code injection vulnerability exists in Pulse Connect Secure <9.1R8 that allows an attacker to crafted a URI to perform an arbitrary code execution via the admin web interface.
cvelistv5
CVE-2020-8204MEDIUMCVSS 6.1≤ 9.0vFixed in 9.1R52020-07-30
CVE-2020-8204 [MEDIUM] CWE-79 CVE-2020-8204: A cross site scripting (XSS) vulnerability exists in Pulse Connect Secure <9.1R5 on the PSAL Page. A cross site scripting (XSS) vulnerability exists in Pulse Connect Secure <9.1R5 on the PSAL Page.
cvelistv5nvd
CVE-2020-8220MEDIUMCVSS 6.5≤ 9.0vFixed in 9.1R82020-07-30
CVE-2020-8220 [MEDIUM] CWE-400 CVE-2020-8220: A denial of service vulnerability exists in Pulse Connect Secure <9.1R8 that allows an authenticated A denial of service vulnerability exists in Pulse Connect Secure <9.1R8 that allows an authenticated attacker to perform command injection via the administrator web which can cause DOS.
cvelistv5nvd
CVE-2020-8217MEDIUMCVSS 5.4≤ 9.0vFixed in 9.1R82020-07-30
CVE-2020-8217 [MEDIUM] CWE-79 CVE-2020-8217: A cross site scripting (XSS) vulnerability in Pulse Connect Secure <9.1R8 allowed attackers to explo A cross site scripting (XSS) vulnerability in Pulse Connect Secure <9.1R8 allowed attackers to exploit in the URL used for Citrix ICA.
cvelistv5nvd
CVE-2020-8216MEDIUMCVSS 4.3≤ 9.0vFixed in 9.1R82020-07-30
CVE-2020-8216 [MEDIUM] CWE-200 CVE-2020-8216: An information disclosure vulnerability in meeting of Pulse Connect Secure <9.1R8 allowed an authent An information disclosure vulnerability in meeting of Pulse Connect Secure <9.1R8 allowed an authenticated end-users to find meeting details, if they know the Meeting ID.
cvelistv5nvd
CVE-2020-8221MEDIUMCVSS 4.9≤ 9.0vFixed in2020-07-30
CVE-2020-8221 [MEDIUM] CWE-22 CVE-2020-8221: A path traversal vulnerability exists in Pulse Connect Secure <9.1R8 which allows an authenticated a A path traversal vulnerability exists in Pulse Connect Secure <9.1R8 which allows an authenticated attacker to read arbitrary files via the administrator web interface.
cvelistv5nvd
CVE-2020-8222MEDIUMCVSS 6.8≤ 9.0vFixed in 9.1R82020-07-30
CVE-2020-8222 [MEDIUM] CWE-22 CVE-2020-8222: A path traversal vulnerability exists in Pulse Connect Secure <9.1R8 that allowed an authenticated a A path traversal vulnerability exists in Pulse Connect Secure <9.1R8 that allowed an authenticated attacker via the administrator web interface to perform an arbitrary file reading vulnerability through Meeting.
cvelistv5nvd
CVE-2020-15408MEDIUMCVSS 4.6≤ 9.12020-07-28
CVE-2020-15408 [MEDIUM] CVE-2020-15408: An issue was discovered in Pulse Secure Pulse Connect Secure before 9.1R8. An authenticated attacker An issue was discovered in Pulse Secure Pulse Connect Secure before 9.1R8. An authenticated attacker can access the admin page console via the end-user web interface because of a rewrite.
nvd
CVE-2020-12880MEDIUMCVSS 5.5≤ 9.02020-07-27
CVE-2020-12880 [MEDIUM] CVE-2020-12880: An issue was discovered in Pulse Policy Secure (PPS) and Pulse Connect Secure (PCS) Virtual Applianc An issue was discovered in Pulse Policy Secure (PPS) and Pulse Connect Secure (PCS) Virtual Appliance before 9.1R8. By manipulating a certain kernel boot parameter, it can be tricked into dropping into a root shell in a pre-install phase where the entire source code of the appliance is available and can be retrieved. (The source code is otherwise inaccessib
nvd
CVE-2020-11580CRITICALCVSS 9.1≤ 2020-04-062020-04-06
CVE-2020-11580 [CRITICAL] CWE-295 CVE-2020-11580: An issue was discovered in Pulse Secure Pulse Connect Secure (PCS) through 2020-04-06. The applet in An issue was discovered in Pulse Secure Pulse Connect Secure (PCS) through 2020-04-06. The applet in tncc.jar, executed on macOS, Linux, and Solaris clients when a Host Checker policy is enforced, accepts an arbitrary SSL certificate.
nvd
CVE-2020-11581HIGHCVSS 8.1≤ 2020-04-062020-04-06
CVE-2020-11581 [HIGH] CWE-78 CVE-2020-11581: An issue was discovered in Pulse Secure Pulse Connect Secure (PCS) through 2020-04-06. The applet in An issue was discovered in Pulse Secure Pulse Connect Secure (PCS) through 2020-04-06. The applet in tncc.jar, executed on macOS, Linux, and Solaris clients when a Host Checker policy is enforced, allows a man-in-the-middle attacker to perform OS command injection attacks (against a client) via shell metacharacters to the doCustomRemediateInstructions
nvd
CVE-2020-11582HIGHCVSS 8.8≤ 2020-04-062020-04-06
CVE-2020-11582 [HIGH] CVE-2020-11582: An issue was discovered in Pulse Secure Pulse Connect Secure (PCS) through 2020-04-06. The applet in An issue was discovered in Pulse Secure Pulse Connect Secure (PCS) through 2020-04-06. The applet in tncc.jar, executed on macOS, Linux, and Solaris clients when a Host Checker policy is enforced, launches a TCP server that accepts local connections on a random port. This can be reached by local HTTP clients, because up to 25 invalid lines are ignored, and be
nvd
CVE-2019-11508HIGHCVSS 7.2v7.42019-05-08
CVE-2019-11508 [HIGH] CWE-22 CVE-2019-11508: In Pulse Secure Pulse Connect Secure (PCS) before 8.1R15.1, 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, In Pulse Secure Pulse Connect Secure (PCS) before 8.1R15.1, 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an authenticated attacker (via the admin web interface) can exploit Directory Traversal to execute arbitrary code on the appliance.
nvd
CVE-2019-11540CRITICALCVSS 9.8v8.3rxv9.0r1+6 more2019-04-26
CVE-2019-11540 [CRITICAL] CVE-2019-11540: In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4 and 8.3RX before 8.3R7.1 and Pulse In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4 and 8.3RX before 8.3R7.1 and Pulse Policy Secure version 9.0RX before 9.0R3.2 and 5.4RX before 5.4R7.1, an unauthenticated, remote attacker can conduct a session hijacking attack.
nvd
CVE-2019-11542HIGHCVSS 7.2v8.1r1.0v8.2r1.0+20 more2019-04-26
CVE-2019-11542 [HIGH] CWE-787 CVE-2019-11542: In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX befor In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1RX before 8.1R15.1 and Pulse Policy Secure version 9.0RX before 9.0R3.2, 5.4RX before 5.4R7.1, 5.3RX before 5.3R12.1, 5.2RX before 5.2R12.1, and 5.1RX before 5.1R15.1, an authenticated attacker (via the admin web interface) can send a
nvd
CVE-2019-11541HIGHCVSS 7.5v8.2r1.0v8.2r1.1+19 more2019-04-26
CVE-2019-11541 [HIGH] CVE-2019-11541: In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, and 8.2RX b In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, and 8.2RX before 8.2R12.1, users using SAML authentication with the Reuse Existing NC (Pulse) Session option may see authentication leaks.
nvd
CVE-2019-11543MEDIUMCVSS 6.1v8.1r1.0v8.1rx+8 more2019-04-26
CVE-2019-11543 [MEDIUM] CWE-79 CVE-2019-11543: XSS exists in the admin web console in Pulse Secure Pulse Connect Secure (PCS) 9.0RX before 9.0R3.4, XSS exists in the admin web console in Pulse Secure Pulse Connect Secure (PCS) 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, and 8.1RX before 8.1R15.1 and Pulse Policy Secure 9.0RX before 9.0R3.2, 5.4RX before 5.4R7.1, and 5.2RX before 5.2R12.1.
nvd
CVE-2019-11213HIGHCVSS 8.1≥ 8.1r1.0, ≤ 8.1r14.0≥ 8.3r1, < 8.3r72019-04-12
CVE-2019-11213 [HIGH] CWE-384 CVE-2019-11213: In Pulse Secure Pulse Desktop Client and Network Connect, an attacker could access session tokens to In Pulse Secure Pulse Desktop Client and Network Connect, an attacker could access session tokens to replay and spoof sessions, and as a result, gain unauthorized access as an end user, a related issue to CVE-2019-1573. (The endpoint would need to be already compromised for exploitation to succeed.) This affects Pulse Desktop Client 5.x before Secure
nvd
CVE-2018-18284HIGHCVSS 8.6≥ 8.2r1.0, < 8.2r12.1≥ 8.3r1, < 8.3r7.1+1 more2018-10-19
CVE-2018-18284 [HIGH] CVE-2018-18284: Artifex Ghostscript 9.25 and earlier allows attackers to bypass a sandbox protection mechanism via v Artifex Ghostscript 9.25 and earlier allows attackers to bypass a sandbox protection mechanism via vectors involving the 1Policy operator.
nvd