PT-2019-12363 · Pulse · Pulse Connect Secure+1

Published

2019-04-26

·

Updated

2024-02-27

·

CVE-2019-11540

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Pulse Connect Secure versions 9.0RX before 9.0R3.4 Pulse Connect Secure versions 8.3RX before 8.3R7.1 Pulse Policy Secure versions 9.0RX before 9.0R3.2 Pulse Policy Secure versions 5.4RX before 5.4R7.1
Description An unauthenticated, remote attacker can conduct a session hijacking attack.
Recommendations For Pulse Connect Secure version 9.0RX, update to version 9.0R3.4 or later. For Pulse Connect Secure version 8.3RX, update to version 8.3R7.1 or later. For Pulse Policy Secure version 9.0RX, update to version 9.0R3.2 or later. For Pulse Policy Secure version 5.4RX, update to version 5.4R7.1 or later.

Exploit

Fix

Related Identifiers

CVE-2019-11540

Affected Products

Pulse Connect Secure
Pulse Policy Secure