PT-2019-3001 · Pulse Secure · Pulse Connect Secure
Meh Chang
+1
·
Published
2019-03-22
·
Updated
2026-06-15
·
CVE-2019-11510
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Pulse Secure Pulse Connect Secure (PCS) versions 8.2 through 8.2R12.1
Pulse Secure Pulse Connect Secure (PCS) versions 8.3 through 8.3R7.1
Pulse Secure Pulse Connect Secure (PCS) versions 9.0 through 9.0R3.4
Description
The issue is related to errors in permission handling, allowing an unauthenticated remote attacker to send a specially crafted URI and perform an arbitrary file reading. This can lead to the disclosure of active users and their plain-text credentials. Over 2,500 Pulse Secure VPN endpoints are potentially affected.
Recommendations
For Pulse Secure Pulse Connect Secure (PCS) versions 8.2 through 8.2R12.1, update to version 8.2R12.1 or later.
For Pulse Secure Pulse Connect Secure (PCS) versions 8.3 through 8.3R7.1, update to version 8.3R7.1 or later.
For Pulse Secure Pulse Connect Secure (PCS) versions 9.0 through 9.0R3.4, update to version 9.0R3.4 or later.
As a temporary workaround, consider restricting access to the vulnerable URI endpoint until a patch is available.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Pulse Connect Secure