PT-2017-12023 · Pulse · Pulse Connect Secure+1

Published

2017-08-29

·

Updated

2024-02-27

·

CVE-2017-11455

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Pulse Connect Secure versions 8.2R1 through 8.2R5 Pulse Connect Secure versions 8.1R1 through 8.1R10 Pulse Policy Secure versions 5.3R1 through 5.3R5 Pulse Policy Secure versions 5.2R1 through 5.2R8 Pulse Policy Secure versions 5.1R1 through 5.1R10
Description The issue allows remote attackers to hijack the authentication of administrators for requests to start tcpdump, related to the lack of anti-CSRF tokens in the diag.cgi component.
Recommendations For Pulse Connect Secure versions 8.2R1 through 8.2R5, consider disabling access to the diag.cgi component until a patch is available. For Pulse Connect Secure versions 8.1R1 through 8.1R10, consider disabling access to the diag.cgi component until a patch is available. For Pulse Policy Secure versions 5.3R1 through 5.3R5, consider disabling access to the diag.cgi component until a patch is available. For Pulse Policy Secure versions 5.2R1 through 5.2R8, consider disabling access to the diag.cgi component until a patch is available. For Pulse Policy Secure versions 5.1R1 through 5.1R10, consider disabling access to the diag.cgi component until a patch is available.

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2017-11455

Affected Products

Pulse Connect Secure
Pulse Policy Secure