ZeroHour

Vulnerabilities

93 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-21826
Pulse Secure version 9.115 and below may be susceptible to client-side http request smuggling, When the application receives a POST request, it ignores the requ

Pulse Secure version 9.115 and below may be susceptible to client-side http request smuggling, When the application receives a POST request, it ignores the request's Content-Length header and leaves the POST body on the TCP/TLS socket. This body ends up prefixing the next HTTP request sent down that connection, this means when someone loads website attacker may be able to make browser issue a POST to the application, enabling XSS.

NVD description · AI analysis pending
5.445%
  • ivanti connect secure
  • ivanti pulse connect secure
CVE-2021-44720
In Ivanti Pulse Secure Pulse Connect Secure (PCS) before 9.1R12, the administrator password is stored in the HTML source code of the "Maintenance > Push Configu

In Ivanti Pulse Secure Pulse Connect Secure (PCS) before 9.1R12, the administrator password is stored in the HTML source code of the "Maintenance > Push Configuration > Targets > Target Name" targets.cgi screen. A read-only administrative user can escalate to a read-write administrative role.

NVD description · AI analysis pending
7.23%
  • ivanti connect secure
  • ivanti pulse connect secure
CVE-2021-22965
A vulnerability in Pulse Connect Secure before 9.1R12.1 could allow an unauthenticated administrator to causes a denial of service when a malformed request is s

A vulnerability in Pulse Connect Secure before 9.1R12.1 could allow an unauthenticated administrator to causes a denial of service when a malformed request is sent to the device.

NVD description · AI analysis pending
7.52%
  • ivanti connect secure
  • ivanti pulse connect secure
CVE-2021-22937
A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator to perform a file write via a maliciously crafted archive uploa

A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator to perform a file write via a maliciously crafted archive uploaded in the administrator web interface.

NVD description · AI analysis pending
7.2
group max
8%
  • ivanti connect secure
  • ivanti pulse connect secure
CVE-2021-22908
A buffer overflow vulnerability exists in Windows File Resource Profiles in 9.X allows a remote authenticated user with privileges to browse SMB shares to execu

A buffer overflow vulnerability exists in Windows File Resource Profiles in 9.X allows a remote authenticated user with privileges to browse SMB shares to execute arbitrary code as the root user. As of version 9.1R3, this permission is not enabled by default.

NVD description · AI analysis pending
8.869%
  • ivanti connect secure
  • ivanti pulse connect secure
CVE-2021-22900
Authenticated Arbitrary File Upload in Ivanti Pulse Connect Secure (CVE-2021-22900)

CVE-2021-22900 is an unrestricted file upload vulnerability in Ivanti Pulse Connect Secure (PCS) that affects versions before 9.1R11.4. It is triggered when an authenticated administrator uploads a maliciously crafted archive through the appliance's administrator web interface, allowing a file write without proper validation. An attacker holding (or who has compromised) administrator credentials can achieve a high-impact file write, classified under code injection (CWE-94), with high confidentiality, integrity and availability impact per the 7.2 CVSS score. Any organization running a Pulse Connect Secure appliance below 9.1R11.4 is affected, and because these are internet-facing enterprise VPN gateways, potentially exposed admin interfaces and appliance compromise are the main risks. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2021-11-03, confirming exploitation in the wild; no public PoC is known, ransomware use is unknown, and EPSS estimates a ~14% probability of exploitation within 30 days (96th percentile).

Do: Upgrade Pulse Connect Secure to 9.1R11.4 or later per vendor instructions, as required by the CISA KEV listing. Because exploitation requires authenticated administrator access, restrict the admin web interface to trusted management networks, review administrator accounts and sessions for compromise, and inspect appliances for unexpected or modified files. Monitor for follow-on vendor guidance on appliance integrity checks.

7.214% KEV
  • Ivanti / Pulse Secure Pulse Connect Secure all versions before 9.1R11.4 (fixed in 9.1R11.4)
  • Ivanti / Pulse Secure Connect Secure (CPE product naming) all versions before 9.1R11.4 (fixed in 9.1R11.4)
largetens of thousands of internet-exposed Pulse Connect Secure appliances (est. 10k-100k systems)
CVE-2021-31922
An HTTP Request Smuggling vulnerability in Pulse Secure Virtual Traffic Manager before 21.1 could allow an attacker to smuggle an HTTP request through an HTTP/2

An HTTP Request Smuggling vulnerability in Pulse Secure Virtual Traffic Manager before 21.1 could allow an attacker to smuggle an HTTP request through an HTTP/2 Header. This vulnerability is resolved in 21.1, 20.3R1, 20.2R1, 20.1R2, 19.2R4, and 18.2R3.

NVD description · AI analysis pending
7.5<1% PoC
  • pulsesecure virtual traffic manager
CVE-2021-22887
A vulnerability in the BIOS of Pulse Secure (PSA-Series Hardware) models PSA5000 and PSA7000 could allow an attacker to compromise BIOS firmware.

A vulnerability in the BIOS of Pulse Secure (PSA-Series Hardware) models PSA5000 and PSA7000 could allow an attacker to compromise BIOS firmware. This vulnerability can be exploited only as part of an attack chain. Before an attacker can compromise the BIOS, they must exploit the device.

NVD description · AI analysis pending
2.3<1%
  • pulsesecure psa-5000 firmware
  • pulsesecure psa-7000 firmware
  • pulsesecure x10slh-f firmware
  • +1 more
CVE-2020-8239
A vulnerability in the Pulse Secure Desktop Client < 9.1R9 is vulnerable to the client registry privilege escalation attack.

A vulnerability in the Pulse Secure Desktop Client < 9.1R9 is vulnerable to the client registry privilege escalation attack. This fix also requires Server Side Upgrade due to Standalone Host Checker Client (Windows) and Windows PDC.

NVD description · AI analysis pending
9.8
group max
2%
  • pulsesecure pulse secure desktop client
CVE-2020-8262
+1 in the same advisory: …8261
A vulnerability in the Pulse Connect Secure / Pulse Policy Secure below 9.1R9 could allow attackers to conduct Cross-Site Scripting (XSS) and Open Redirection f

A vulnerability in the Pulse Connect Secure / Pulse Policy Secure below 9.1R9 could allow attackers to conduct Cross-Site Scripting (XSS) and Open Redirection for authenticated user web interface.

NVD description · AI analysis pending
6.1
group max
2%
  • ivanti connect secure
  • ivanti policy secure
  • ivanti pulse connect secure
  • +1 more
CVE-2020-8956
Pulse Secure Desktop Client 9.0Rx before 9.0R5 and 9.1Rx before 9.1R4 on Windows reveals users' passwords if Save Settings is enabled.

Pulse Secure Desktop Client 9.0Rx before 9.0R5 and 9.1Rx before 9.1R4 on Windows reveals users' passwords if Save Settings is enabled.

NVD description · AI analysis pending
3.31%
  • pulsesecure pulse secure desktop
CVE-2020-15352
An XML external entity (XXE) vulnerability in Pulse Connect Secure (PCS) before 9.1R9 and Pulse Policy Secure (PPS) before 9.1R9 allows remote authenticated adm

An XML external entity (XXE) vulnerability in Pulse Connect Secure (PCS) before 9.1R9 and Pulse Policy Secure (PPS) before 9.1R9 allows remote authenticated admins to conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML request.

NVD description · AI analysis pending
7.23%
  • ivanti connect secure
  • ivanti pulse connect secure
  • ivanti policy secure
  • +1 more
CVE-2020-8238
+1 in the same advisory: …8256
A vulnerability in the authenticated user web interface of Pulse Connect Secure and Pulse Policy Secure < 9.1R8.2 could allow attackers to conduct Cross-Site Sc

A vulnerability in the authenticated user web interface of Pulse Connect Secure and Pulse Policy Secure < 9.1R8.2 could allow attackers to conduct Cross-Site Scripting (XSS).

NVD description · AI analysis pending
6.1
group max
2% PoC
  • ivanti connect secure
  • ivanti policy secure
  • ivanti pulse connect secure
  • +1 more
CVE-2020-8206
An improper authentication vulnerability exists in Pulse Connect Secure <9.1RB that allows an attacker with a users primary credentials to bypass the Google TOT

An improper authentication vulnerability exists in Pulse Connect Secure <9.1RB that allows an attacker with a users primary credentials to bypass the Google TOTP.

NVD description · AI analysis pending
8.1
group max
3%
  • ivanti connect secure
  • ivanti pulse connect secure
  • ivanti policy secure
  • +1 more
CVE-2020-8218
Code Injection RCE in Pulse Connect Secure Admin Web Interface

CVE-2020-8218 is a code injection vulnerability (CWE-94) in the admin web interface of Pulse Secure's Pulse Connect Secure SSL VPN appliance. An attacker triggers it by sending a specially crafted URI to the admin web interface, resulting in arbitrary code execution on the appliance. Successful exploitation gives the attacker code execution on the VPN gateway and a foothold from which internal networks behind the appliance could be reached. All organizations running Pulse Connect Secure are affected, particularly those whose admin web interface is reachable by untrusted users. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-07), confirming in-the-wild exploitation, and its 98th-percentile EPSS score (32.7% probability of exploitation within 30 days) indicates elevated risk; no public proof-of-concept is known.

Do: Apply the latest Pulse Connect Secure maintenance update per the vendor's instructions, as required by the CISA KEV listing. Until patched, restrict the admin web interface to trusted management networks or jump hosts and review admin interface logs for unusual crafted-URI requests or signs of post-exploitation. Because ransomware use is listed as unknown, treat any unpatched, internet-reachable appliance as high priority for patching and compromise assessment.

7.233% KEV PoC
  • Pulse Secure Pulse Connect Secure
largetens of thousands of internet-exposed Pulse Connect Secure appliances (public internet scans showed roughly 20,000-30,000+)
CVE-2020-15408
An issue was discovered in Pulse Secure Pulse Connect Secure before 9.1R8.

An issue was discovered in Pulse Secure Pulse Connect Secure before 9.1R8. An authenticated attacker can access the admin page console via the end-user web interface because of a rewrite.

NVD description · AI analysis pending
4.6<1%
  • pulsesecure pulse connect secure
  • pulsesecure pulse secure desktop client
CVE-2020-12880
An issue was discovered in Pulse Policy Secure (PPS) and Pulse Connect Secure (PCS) Virtual Appliance before 9.1R8.

An issue was discovered in Pulse Policy Secure (PPS) and Pulse Connect Secure (PCS) Virtual Appliance before 9.1R8. By manipulating a certain kernel boot parameter, it can be tricked into dropping into a root shell in a pre-install phase where the entire source code of the appliance is available and can be retrieved. (The source code is otherwise inaccessible because the appliance has its hard disks encrypted, and no root shell is available during normal operation.)

NVD description · AI analysis pending
5.5<1%
  • ivanti connect secure
  • ivanti pulse connect secure
  • ivanti policy secure
  • +1 more
CVE-2020-13162
A time-of-check time-of-use vulnerability in PulseSecureService.exe in Pulse Secure Client versions prior to 9.1.6 down to 5.3 R70 for Windows (which runs as NT

A time-of-check time-of-use vulnerability in PulseSecureService.exe in Pulse Secure Client versions prior to 9.1.6 down to 5.3 R70 for Windows (which runs as NT AUTHORITY/SYSTEM) allows unprivileged users to run a Microsoft Installer executable with elevated privileges.

NVD description · AI analysis pending
7.0<1% PoC
  • pulsesecure pulse secure desktop client
  • pulsesecure pulse secure installer service
CVE-2020-11580
+2 in the same advisory: …11582 …11581
An issue was discovered in Pulse Secure Pulse Connect Secure (PCS) through 2020-04-06.

An issue was discovered in Pulse Secure Pulse Connect Secure (PCS) through 2020-04-06. The applet in tncc.jar, executed on macOS, Linux, and Solaris clients when a Host Checker policy is enforced, accepts an arbitrary SSL certificate.

NVD description · AI analysis pending
9.1
group max
1% PoC
  • pulsesecure pulse connect secure
  • pulsesecure pulse policy secure
CVE-2018-20810
+2 in the same advisory: …20809 …20814
Session data between cluster nodes during cluster synchronization is not properly encrypted in Pulse Secure Pulse Connect Secure (PCS) 8.3RX before 8.3R2 and Pu

Session data between cluster nodes during cluster synchronization is not properly encrypted in Pulse Secure Pulse Connect Secure (PCS) 8.3RX before 8.3R2 and Pulse Policy Secure (PPS) 5.4RX before 5.4R2. This is not applicable to PCS 8.1RX, PPS 5.2RX, or stand-alone devices.

NVD description · AI analysis pending
9.8
group max
2%
  • ivanti connect secure
  • ivanti pulse policy secure
CVE-2018-20812
An information exposure issue where IPv6 DNS traffic would be sent outside of the VPN tunnel (when Traffic Enforcement was enabled) exists in Pulse Secure Pulse

An information exposure issue where IPv6 DNS traffic would be sent outside of the VPN tunnel (when Traffic Enforcement was enabled) exists in Pulse Secure Pulse Secure Desktop 9.0R1 and below. This is applicable only to dual-stack (IPv4/IPv6) endpoints.

NVD description · AI analysis pending
7.51%
  • pulsesecure pulse secure desktop client
CVE-2019-11477
+1 in the same advisory: …11478
Jonathan Looney discovered that the TCP_SKB_CB(skb)->tcp_gso_segs value was subject to an integer overflow in the Linux kernel when handling TCP Selective Ackno

Jonathan Looney discovered that the TCP_SKB_CB(skb)->tcp_gso_segs value was subject to an integer overflow in the Linux kernel when handling TCP Selective Acknowledgments (SACKs). A remote attacker could use this to cause a denial of service. This has been fixed in stable kernel releases 4.4.182, 4.9.182, 4.14.127, 4.19.52, 5.1.11, and is fixed in commit 3b4929f65b0d8249f19a50245cd88ed1a2f78cff.

NVD description · AI analysis pending
7.599%
  • linux linux kernel
  • linux big-ip advanced firewall manager
  • linux big-ip access policy manager
  • +1 more
CVE-2019-11509
In Pulse Secure Pulse Connect Secure (PCS) before 8.1R15.1, 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4 and Pulse Policy Secure (PPS) before

In Pulse Secure Pulse Connect Secure (PCS) before 8.1R15.1, 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4 and Pulse Policy Secure (PPS) before 5.1R15.1, 5.2 before 5.2R12.1, 5.3 before 5.3R15.1, 5.4 before 5.4R7.1, and 9.0 before 9.0R3.2, an authenticated attacker (via the admin web interface) can exploit Incorrect Access Control to execute arbitrary code on the appliance.

NVD description · AI analysis pending
8.88%
  • ivanti connect secure
  • ivanti policy secure
  • ivanti pulse policy secure