Vulnerabilities
93 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2022-21826 | Pulse Secure version 9.115 and below may be susceptible to client-side http request smuggling, When the application receives a POST request, it ignores the requ Pulse Secure version 9.115 and below may be susceptible to client-side http request smuggling, When the application receives a POST request, it ignores the request's Content-Length header and leaves the POST body on the TCP/TLS socket. This body ends up prefixing the next HTTP request sent down that connection, this means when someone loads website attacker may be able to make browser issue a POST to the application, enabling XSS. NVD description · AI analysis pending | 5.4 | 45% |
| — | ||
| CVE-2021-44720 | In Ivanti Pulse Secure Pulse Connect Secure (PCS) before 9.1R12, the administrator password is stored in the HTML source code of the "Maintenance > Push Configu In Ivanti Pulse Secure Pulse Connect Secure (PCS) before 9.1R12, the administrator password is stored in the HTML source code of the "Maintenance > Push Configuration > Targets > Target Name" targets.cgi screen. A read-only administrative user can escalate to a read-write administrative role. NVD description · AI analysis pending | 7.2 | 3% |
| — | ||
| CVE-2021-22965 | A vulnerability in Pulse Connect Secure before 9.1R12.1 could allow an unauthenticated administrator to causes a denial of service when a malformed request is s A vulnerability in Pulse Connect Secure before 9.1R12.1 could allow an unauthenticated administrator to causes a denial of service when a malformed request is sent to the device. NVD description · AI analysis pending | 7.5 | 2% |
| — | ||
| CVE-2021-22937 | A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator to perform a file write via a maliciously crafted archive uploa A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator to perform a file write via a maliciously crafted archive uploaded in the administrator web interface. NVD description · AI analysis pending | 7.2 group max | 8% |
| — | ||
| CVE-2021-22908 | A buffer overflow vulnerability exists in Windows File Resource Profiles in 9.X allows a remote authenticated user with privileges to browse SMB shares to execu A buffer overflow vulnerability exists in Windows File Resource Profiles in 9.X allows a remote authenticated user with privileges to browse SMB shares to execute arbitrary code as the root user. As of version 9.1R3, this permission is not enabled by default. NVD description · AI analysis pending | 8.8 | 69% |
| — | ||
| CVE-2021-22900 | Authenticated Arbitrary File Upload in Ivanti Pulse Connect Secure (CVE-2021-22900) CVE-2021-22900 is an unrestricted file upload vulnerability in Ivanti Pulse Connect Secure (PCS) that affects versions before 9.1R11.4. It is triggered when an authenticated administrator uploads a maliciously crafted archive through the appliance's administrator web interface, allowing a file write without proper validation. An attacker holding (or who has compromised) administrator credentials can achieve a high-impact file write, classified under code injection (CWE-94), with high confidentiality, integrity and availability impact per the 7.2 CVSS score. Any organization running a Pulse Connect Secure appliance below 9.1R11.4 is affected, and because these are internet-facing enterprise VPN gateways, potentially exposed admin interfaces and appliance compromise are the main risks. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2021-11-03, confirming exploitation in the wild; no public PoC is known, ransomware use is unknown, and EPSS estimates a ~14% probability of exploitation within 30 days (96th percentile). Do: Upgrade Pulse Connect Secure to 9.1R11.4 or later per vendor instructions, as required by the CISA KEV listing. Because exploitation requires authenticated administrator access, restrict the admin web interface to trusted management networks, review administrator accounts and sessions for compromise, and inspect appliances for unexpected or modified files. Monitor for follow-on vendor guidance on appliance integrity checks. | 7.2 | 14% | KEV |
| largetens of thousands of internet-exposed Pulse Connect Secure appliances (est. 10k-100k systems) | |
| CVE-2021-31922 | An HTTP Request Smuggling vulnerability in Pulse Secure Virtual Traffic Manager before 21.1 could allow an attacker to smuggle an HTTP request through an HTTP/2 An HTTP Request Smuggling vulnerability in Pulse Secure Virtual Traffic Manager before 21.1 could allow an attacker to smuggle an HTTP request through an HTTP/2 Header. This vulnerability is resolved in 21.1, 20.3R1, 20.2R1, 20.1R2, 19.2R4, and 18.2R3. NVD description · AI analysis pending | 7.5 | <1% | PoC |
| — | |
| CVE-2021-22887 | A vulnerability in the BIOS of Pulse Secure (PSA-Series Hardware) models PSA5000 and PSA7000 could allow an attacker to compromise BIOS firmware. A vulnerability in the BIOS of Pulse Secure (PSA-Series Hardware) models PSA5000 and PSA7000 could allow an attacker to compromise BIOS firmware. This vulnerability can be exploited only as part of an attack chain. Before an attacker can compromise the BIOS, they must exploit the device. NVD description · AI analysis pending | 2.3 | <1% |
| — | ||
| CVE-2020-8239 | A vulnerability in the Pulse Secure Desktop Client < 9.1R9 is vulnerable to the client registry privilege escalation attack. A vulnerability in the Pulse Secure Desktop Client < 9.1R9 is vulnerable to the client registry privilege escalation attack. This fix also requires Server Side Upgrade due to Standalone Host Checker Client (Windows) and Windows PDC. NVD description · AI analysis pending | 9.8 group max | 2% |
| — | ||
| CVE-2020-8262 +1 in the same advisory: …8261 | A vulnerability in the Pulse Connect Secure / Pulse Policy Secure below 9.1R9 could allow attackers to conduct Cross-Site Scripting (XSS) and Open Redirection f A vulnerability in the Pulse Connect Secure / Pulse Policy Secure below 9.1R9 could allow attackers to conduct Cross-Site Scripting (XSS) and Open Redirection for authenticated user web interface. NVD description · AI analysis pending | 6.1 group max | 2% |
| — | ||
| CVE-2020-8956 | Pulse Secure Desktop Client 9.0Rx before 9.0R5 and 9.1Rx before 9.1R4 on Windows reveals users' passwords if Save Settings is enabled. Pulse Secure Desktop Client 9.0Rx before 9.0R5 and 9.1Rx before 9.1R4 on Windows reveals users' passwords if Save Settings is enabled. NVD description · AI analysis pending | 3.3 | 1% |
| — | ||
| CVE-2020-15352 | An XML external entity (XXE) vulnerability in Pulse Connect Secure (PCS) before 9.1R9 and Pulse Policy Secure (PPS) before 9.1R9 allows remote authenticated adm An XML external entity (XXE) vulnerability in Pulse Connect Secure (PCS) before 9.1R9 and Pulse Policy Secure (PPS) before 9.1R9 allows remote authenticated admins to conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML request. NVD description · AI analysis pending | 7.2 | 3% |
| — | ||
| CVE-2020-8238 +1 in the same advisory: …8256 | A vulnerability in the authenticated user web interface of Pulse Connect Secure and Pulse Policy Secure < 9.1R8.2 could allow attackers to conduct Cross-Site Sc A vulnerability in the authenticated user web interface of Pulse Connect Secure and Pulse Policy Secure < 9.1R8.2 could allow attackers to conduct Cross-Site Scripting (XSS). NVD description · AI analysis pending | 6.1 group max | 2% | PoC |
| — | |
| CVE-2020-8206 | An improper authentication vulnerability exists in Pulse Connect Secure <9.1RB that allows an attacker with a users primary credentials to bypass the Google TOT An improper authentication vulnerability exists in Pulse Connect Secure <9.1RB that allows an attacker with a users primary credentials to bypass the Google TOTP. NVD description · AI analysis pending | 8.1 group max | 3% |
| — | ||
| CVE-2020-8218 | Code Injection RCE in Pulse Connect Secure Admin Web Interface CVE-2020-8218 is a code injection vulnerability (CWE-94) in the admin web interface of Pulse Secure's Pulse Connect Secure SSL VPN appliance. An attacker triggers it by sending a specially crafted URI to the admin web interface, resulting in arbitrary code execution on the appliance. Successful exploitation gives the attacker code execution on the VPN gateway and a foothold from which internal networks behind the appliance could be reached. All organizations running Pulse Connect Secure are affected, particularly those whose admin web interface is reachable by untrusted users. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-07), confirming in-the-wild exploitation, and its 98th-percentile EPSS score (32.7% probability of exploitation within 30 days) indicates elevated risk; no public proof-of-concept is known. Do: Apply the latest Pulse Connect Secure maintenance update per the vendor's instructions, as required by the CISA KEV listing. Until patched, restrict the admin web interface to trusted management networks or jump hosts and review admin interface logs for unusual crafted-URI requests or signs of post-exploitation. Because ransomware use is listed as unknown, treat any unpatched, internet-reachable appliance as high priority for patching and compromise assessment. | 7.2 | 33% | KEV PoC |
| largetens of thousands of internet-exposed Pulse Connect Secure appliances (public internet scans showed roughly 20,000-30,000+) | |
| CVE-2020-15408 | An issue was discovered in Pulse Secure Pulse Connect Secure before 9.1R8. An issue was discovered in Pulse Secure Pulse Connect Secure before 9.1R8. An authenticated attacker can access the admin page console via the end-user web interface because of a rewrite. NVD description · AI analysis pending | 4.6 | <1% |
| — | ||
| CVE-2020-12880 | An issue was discovered in Pulse Policy Secure (PPS) and Pulse Connect Secure (PCS) Virtual Appliance before 9.1R8. An issue was discovered in Pulse Policy Secure (PPS) and Pulse Connect Secure (PCS) Virtual Appliance before 9.1R8. By manipulating a certain kernel boot parameter, it can be tricked into dropping into a root shell in a pre-install phase where the entire source code of the appliance is available and can be retrieved. (The source code is otherwise inaccessible because the appliance has its hard disks encrypted, and no root shell is available during normal operation.) NVD description · AI analysis pending | 5.5 | <1% |
| — | ||
| CVE-2020-13162 | A time-of-check time-of-use vulnerability in PulseSecureService.exe in Pulse Secure Client versions prior to 9.1.6 down to 5.3 R70 for Windows (which runs as NT A time-of-check time-of-use vulnerability in PulseSecureService.exe in Pulse Secure Client versions prior to 9.1.6 down to 5.3 R70 for Windows (which runs as NT AUTHORITY/SYSTEM) allows unprivileged users to run a Microsoft Installer executable with elevated privileges. NVD description · AI analysis pending | 7.0 | <1% | PoC |
| — | |
| CVE-2020-11580 | An issue was discovered in Pulse Secure Pulse Connect Secure (PCS) through 2020-04-06. An issue was discovered in Pulse Secure Pulse Connect Secure (PCS) through 2020-04-06. The applet in tncc.jar, executed on macOS, Linux, and Solaris clients when a Host Checker policy is enforced, accepts an arbitrary SSL certificate. NVD description · AI analysis pending | 9.1 group max | 1% | PoC |
| — | |
| CVE-2018-20810 | Session data between cluster nodes during cluster synchronization is not properly encrypted in Pulse Secure Pulse Connect Secure (PCS) 8.3RX before 8.3R2 and Pu Session data between cluster nodes during cluster synchronization is not properly encrypted in Pulse Secure Pulse Connect Secure (PCS) 8.3RX before 8.3R2 and Pulse Policy Secure (PPS) 5.4RX before 5.4R2. This is not applicable to PCS 8.1RX, PPS 5.2RX, or stand-alone devices. NVD description · AI analysis pending | 9.8 group max | 2% |
| — | ||
| CVE-2018-20812 | An information exposure issue where IPv6 DNS traffic would be sent outside of the VPN tunnel (when Traffic Enforcement was enabled) exists in Pulse Secure Pulse An information exposure issue where IPv6 DNS traffic would be sent outside of the VPN tunnel (when Traffic Enforcement was enabled) exists in Pulse Secure Pulse Secure Desktop 9.0R1 and below. This is applicable only to dual-stack (IPv4/IPv6) endpoints. NVD description · AI analysis pending | 7.5 | 1% |
| — | ||
| CVE-2019-11477 +1 in the same advisory: …11478 | Jonathan Looney discovered that the TCP_SKB_CB(skb)->tcp_gso_segs value was subject to an integer overflow in the Linux kernel when handling TCP Selective Ackno Jonathan Looney discovered that the TCP_SKB_CB(skb)->tcp_gso_segs value was subject to an integer overflow in the Linux kernel when handling TCP Selective Acknowledgments (SACKs). A remote attacker could use this to cause a denial of service. This has been fixed in stable kernel releases 4.4.182, 4.9.182, 4.14.127, 4.19.52, 5.1.11, and is fixed in commit 3b4929f65b0d8249f19a50245cd88ed1a2f78cff. NVD description · AI analysis pending | 7.5 | 99% |
| — | ||
| CVE-2019-11509 | In Pulse Secure Pulse Connect Secure (PCS) before 8.1R15.1, 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4 and Pulse Policy Secure (PPS) before In Pulse Secure Pulse Connect Secure (PCS) before 8.1R15.1, 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4 and Pulse Policy Secure (PPS) before 5.1R15.1, 5.2 before 5.2R12.1, 5.3 before 5.3R15.1, 5.4 before 5.4R7.1, and 9.0 before 9.0R3.2, an authenticated attacker (via the admin web interface) can exploit Incorrect Access Control to execute arbitrary code on the appliance. NVD description · AI analysis pending | 8.8 | 8% |
| — |