PT-2019-12343 · Pulse · Pulse Connect Secure+1

Published

2019-06-03

·

Updated

2024-02-27

·

CVE-2019-11509

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Pulse Connect Secure (PCS) versions 8.1 before 8.1R15.1 Pulse Connect Secure (PCS) versions 8.2 before 8.2R12.1 Pulse Connect Secure (PCS) versions 8.3 before 8.3R7.1 Pulse Connect Secure (PCS) versions 9.0 before 9.0R3.4 Pulse Policy Secure (PPS) versions 5.1 before 5.1R15.1 Pulse Policy Secure (PPS) versions 5.2 before 5.2R12.1 Pulse Policy Secure (PPS) versions 5.3 before 5.3R15.1 Pulse Policy Secure (PPS) versions 5.4 before 5.4R7.1 Pulse Policy Secure (PPS) versions 9.0 before 9.0R3.2
Description An authenticated attacker, via the admin web interface, can exploit Incorrect Access Control to execute arbitrary code on the appliance.
Recommendations For Pulse Connect Secure (PCS) versions 8.1 before 8.1R15.1, update to version 8.1R15.1 or later. For Pulse Connect Secure (PCS) versions 8.2 before 8.2R12.1, update to version 8.2R12.1 or later. For Pulse Connect Secure (PCS) versions 8.3 before 8.3R7.1, update to version 8.3R7.1 or later. For Pulse Connect Secure (PCS) versions 9.0 before 9.0R3.4, update to version 9.0R3.4 or later. For Pulse Policy Secure (PPS) versions 5.1 before 5.1R15.1, update to version 5.1R15.1 or later. For Pulse Policy Secure (PPS) versions 5.2 before 5.2R12.1, update to version 5.2R12.1 or later. For Pulse Policy Secure (PPS) versions 5.3 before 5.3R15.1, update to version 5.3R15.1 or later. For Pulse Policy Secure (PPS) versions 5.4 before 5.4R7.1, update to version 5.4R7.1 or later. For Pulse Policy Secure (PPS) versions 9.0 before 9.0R3.2, update to version 9.0R3.2 or later.

Fix

Related Identifiers

CVE-2019-11509

Affected Products

Pulse Connect Secure
Pulse Policy Secure