Pulsesecure Pulse Policy Secure vulnerabilities
27 known vulnerabilities affecting pulsesecure/pulse_policy_secure.
Total CVEs
27
CISA KEV
2
actively exploited
Public exploits
1
Exploited in wild
2
Severity breakdown
CRITICAL5HIGH9MEDIUM13
Vulnerabilities
Page 2 of 2
CVE-2019-11542HIGHCVSS 7.2v5.1r1.0v5.1r1.1+70 more2019-04-26
CVE-2019-11542 [HIGH] CWE-787 CVE-2019-11542: In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX befor
In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1RX before 8.1R15.1 and Pulse Policy Secure version 9.0RX before 9.0R3.2, 5.4RX before 5.4R7.1, 5.3RX before 5.3R12.1, 5.2RX before 5.2R12.1, and 5.1RX before 5.1R15.1, an authenticated attacker (via the admin web interface) can send a
nvd
CVE-2019-11539HIGHCVSS 7.2KEVPoCv5.1r1.0v5.1r1.1+64 more2019-04-26
CVE-2019-11539 [HIGH] CWE-78 CVE-2019-11539: In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX befor
In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1RX before 8.1R15.1 and Pulse Policy Secure version 9.0RX before 9.0R3.2, 5.4RX before 5.4R7.1, 5.3RX before 5.3R12.1, 5.2RX before 5.2R12.1, and 5.1RX before 5.1R15.1, the admin web interface allows an authenticated attacker to inject
nvd
CVE-2019-11543MEDIUMCVSS 6.1v5.2r1.0v5.2r2.0+30 more2019-04-26
CVE-2019-11543 [MEDIUM] CWE-79 CVE-2019-11543: XSS exists in the admin web console in Pulse Secure Pulse Connect Secure (PCS) 9.0RX before 9.0R3.4,
XSS exists in the admin web console in Pulse Secure Pulse Connect Secure (PCS) 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, and 8.1RX before 8.1R15.1 and Pulse Policy Secure 9.0RX before 9.0R3.2, 5.4RX before 5.4R7.1, and 5.2RX before 5.2R12.1.
nvd
CVE-2018-6320CRITICALCVSS 9.8v5.2r1.0v5.2r2.0+12 more2018-09-06
CVE-2018-6320 [CRITICAL] CWE-20 CVE-2018-6320: A vulnerability has been discovered in login.cgi in Pulse Secure Pulse Connect Secure (PCS) 8.1RX be
A vulnerability has been discovered in login.cgi in Pulse Secure Pulse Connect Secure (PCS) 8.1RX before 8.1R12 and 8.3RX before 8.3R2 and Pulse Policy Secure (PPS) 5.2RX before 5.2R9 and 5.4RX before 5.4R2 wherein an http(s) Host header received from the browser is trusted without validation.
nvd
CVE-2018-14366MEDIUMCVSS 6.1v5.2r1.0v5.2r2.0+16 more2018-09-06
CVE-2018-14366 [MEDIUM] CWE-601 CVE-2018-14366: download.cgi in Pulse Secure Pulse Connect Secure 8.1RX before 8.1R13 and 8.3RX before 8.3R4 and Pul
download.cgi in Pulse Secure Pulse Connect Secure 8.1RX before 8.1R13 and 8.3RX before 8.3R4 and Pulse Policy Secure through 5.2RX before 5.2R10 and 5.4RX before 5.4R4 have an Open Redirect Vulnerability.
nvd
CVE-2018-5299CRITICALCVSS 9.8≥ 5.4r1, ≤ 5.4r32018-01-16
CVE-2018-5299 [CRITICAL] CWE-787 CVE-2018-5299: A stack-based Buffer Overflow Vulnerability exists in the web server in Pulse Secure Pulse Connect S
A stack-based Buffer Overflow Vulnerability exists in the web server in Pulse Secure Pulse Connect Secure (PCS) before 8.3R4 and Pulse Policy Secure (PPS) before 5.4R4, leading to memory corruption and possibly remote code execution.
nvd
CVE-2017-11455HIGHCVSS 8.8v5.1r1.0v5.1r1.1+35 more2017-08-29
CVE-2017-11455 [HIGH] CWE-352 CVE-2017-11455: diag.cgi in Pulse Connect Secure 8.2R1 through 8.2R5, 8.1R1 through 8.1R10 and Pulse Policy Secure 5
diag.cgi in Pulse Connect Secure 8.2R1 through 8.2R5, 8.1R1 through 8.1R10 and Pulse Policy Secure 5.3R1 through 5.3R5, 5.2R1 through 5.2R8, and 5.1R1 through 5.1R10 allow remote attackers to hijack the authentication of administrators for requests to start tcpdump, related to the lack of anti-CSRF tokens.
nvd
← Previous2 / 2