Show filters
93 Total Results
Displaying 11-20 of 93
Sort by:
Attacker Value
Unknown

CVE-2021-22936

Disclosure Date: August 16, 2021 (last updated February 28, 2024)
A vulnerability in Pulse Connect Secure before 9.1R12 could allow a threat actor to perform a cross-site script attack against an authenticated administrator via an unsanitized web parameter.
Attacker Value
Unknown

CVE-2021-22937

Disclosure Date: August 16, 2021 (last updated February 28, 2024)
A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator to perform a file write via a maliciously crafted archive uploaded in the administrator web interface.
Attacker Value
Unknown

CVE-2021-22938

Disclosure Date: August 16, 2021 (last updated February 28, 2024)
A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator to perform command injection via an unsanitized web parameter in the administrator web console.
Attacker Value
Unknown

CVE-2021-22934

Disclosure Date: August 16, 2021 (last updated February 28, 2024)
A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator or compromised Pulse Connect Secure device in a load-balanced configuration to perform a buffer overflow via a malicious crafted web request.
Attacker Value
Unknown

CVE-2021-22900

Disclosure Date: May 27, 2021 (last updated February 28, 2024)
A vulnerability allowed multiple unrestricted uploads in Pulse Connect Secure before 9.1R11.4 that could lead to an authenticated administrator to perform a file write via a maliciously crafted archive upload in the administrator web interface.
Attacker Value
Unknown

CVE-2021-22908

Disclosure Date: May 27, 2021 (last updated February 28, 2024)
A buffer overflow vulnerability exists in Windows File Resource Profiles in 9.X allows a remote authenticated user with privileges to browse SMB shares to execute arbitrary code as the root user. As of version 9.1R3, this permission is not enabled by default.
Attacker Value
Unknown

CVE-2021-31922

Disclosure Date: May 14, 2021 (last updated November 28, 2024)
An HTTP Request Smuggling vulnerability in Pulse Secure Virtual Traffic Manager before 21.1 could allow an attacker to smuggle an HTTP request through an HTTP/2 Header. This vulnerability is resolved in 21.1, 20.3R1, 20.2R1, 20.1R2, 19.2R4, and 18.2R3.
Attacker Value
Unknown

CVE-2021-22887

Disclosure Date: March 16, 2021 (last updated November 28, 2024)
A vulnerability in the BIOS of Pulse Secure (PSA-Series Hardware) models PSA5000 and PSA7000 could allow an attacker to compromise BIOS firmware. This vulnerability can be exploited only as part of an attack chain. Before an attacker can compromise the BIOS, they must exploit the device.
Attacker Value
Unknown

CVE-2020-8239

Disclosure Date: October 28, 2020 (last updated November 28, 2024)
A vulnerability in the Pulse Secure Desktop Client < 9.1R9 is vulnerable to the client registry privilege escalation attack. This fix also requires Server Side Upgrade due to Standalone Host Checker Client (Windows) and Windows PDC.
Attacker Value
Unknown

CVE-2020-8254

Disclosure Date: October 28, 2020 (last updated November 28, 2024)
A vulnerability in the Pulse Secure Desktop Client < 9.1R9 has Remote Code Execution (RCE) if users can be convinced to connect to a malicious server. This vulnerability only affects Windows PDC.To improve the security of connections between Pulse clients and Pulse Connect Secure, see below recommendation(s):Disable Dynamic certificate trust for PDC.