PT-2019-12342 · Pulse Secure · Pulse Connect Secure

Meh Chang

+1

·

Publicado

2019-05-08

·

Atualizado

2024-02-27

·

CVE-2019-11508

CVSS v3.1

8.6

Alta

VetorAC:L/AV:N/A:N/C:H/I:N/PR:N/S:C/UI:N
Name of the Vulnerable Software and Affected Versions Pulse Secure Pulse Connect Secure (PCS) versions 8.1R15.0 and earlier Pulse Secure Pulse Connect Secure (PCS) versions 8.2R12.0 and earlier Pulse Secure Pulse Connect Secure (PCS) versions 8.3R7.0 and earlier Pulse Secure Pulse Connect Secure (PCS) versions 9.0R3.3 and earlier
Description The issue allows an authenticated attacker, via the admin web interface, to exploit Directory Traversal and execute arbitrary code on the appliance.
Recommendations For versions 8.1R15.0 and earlier, update to version 8.1R15.1 or later. For versions 8.2R12.0 and earlier, update to version 8.2R12.1 or later. For versions 8.3R7.0 and earlier, update to version 8.3R7.1 or later. For versions 9.0R3.3 and earlier, update to version 9.0R3.4 or later.

Exploit

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-11508

Produtos afetados

Pulse Connect Secure