Show filters
242 Total Results
Displaying 141-150 of 242
Sort by:
Attacker Value
Unknown
CVE-2020-8221
Disclosure Date: July 30, 2020 (last updated February 21, 2025)
A path traversal vulnerability exists in Pulse Connect Secure <9.1R8 which allows an authenticated attacker to read arbitrary files via the administrator web interface.
0
Attacker Value
Unknown
CVE-2020-8220
Disclosure Date: July 30, 2020 (last updated February 21, 2025)
A denial of service vulnerability exists in Pulse Connect Secure <9.1R8 that allows an authenticated attacker to perform command injection via the administrator web which can cause DOS.
0
Attacker Value
Unknown
CVE-2020-8206
Disclosure Date: July 30, 2020 (last updated February 21, 2025)
An improper authentication vulnerability exists in Pulse Connect Secure <9.1RB that allows an attacker with a users primary credentials to bypass the Google TOTP.
0
Attacker Value
Unknown
CVE-2020-12880
Disclosure Date: July 27, 2020 (last updated February 28, 2024)
An issue was discovered in Pulse Policy Secure (PPS) and Pulse Connect Secure (PCS) Virtual Appliance before 9.1R8. By manipulating a certain kernel boot parameter, it can be tricked into dropping into a root shell in a pre-install phase where the entire source code of the appliance is available and can be retrieved. (The source code is otherwise inaccessible because the appliance has its hard disks encrypted, and no root shell is available during normal operation.)
0
Attacker Value
Unknown
CVE-2020-11580
Disclosure Date: April 06, 2020 (last updated February 21, 2025)
An issue was discovered in Pulse Secure Pulse Connect Secure (PCS) through 2020-04-06. The applet in tncc.jar, executed on macOS, Linux, and Solaris clients when a Host Checker policy is enforced, accepts an arbitrary SSL certificate.
0
Attacker Value
Unknown
CVE-2020-11582
Disclosure Date: April 06, 2020 (last updated February 21, 2025)
An issue was discovered in Pulse Secure Pulse Connect Secure (PCS) through 2020-04-06. The applet in tncc.jar, executed on macOS, Linux, and Solaris clients when a Host Checker policy is enforced, launches a TCP server that accepts local connections on a random port. This can be reached by local HTTP clients, because up to 25 invalid lines are ignored, and because DNS rebinding can occur. (This server accepts, for example, a setcookie command that might be relevant to CVE-2020-11581 exploitation.)
0
Attacker Value
Unknown
CVE-2020-11581
Disclosure Date: April 06, 2020 (last updated February 21, 2025)
An issue was discovered in Pulse Secure Pulse Connect Secure (PCS) through 2020-04-06. The applet in tncc.jar, executed on macOS, Linux, and Solaris clients when a Host Checker policy is enforced, allows a man-in-the-middle attacker to perform OS command injection attacks (against a client) via shell metacharacters to the doCustomRemediateInstructions method, because Runtime.getRuntime().exec() is used.
0
Attacker Value
Unknown
CVE-2019-16007
Disclosure Date: January 08, 2020 (last updated February 22, 2025)
A vulnerability in the inter-service communication of Cisco AnyConnect Secure Mobility Client for Android could allow an unauthenticated, local attacker to perform a service hijack attack on an affected device or cause a denial of service (DoS) condition. The vulnerability is due to the use of implicit service invocations. An attacker could exploit this vulnerability by persuading a user to install a malicious application. A successful exploit could allow the attacker to access confidential user information or cause a DoS condition on the AnyConnect application.
0
Attacker Value
Unknown
CVE-2018-20811
Disclosure Date: June 28, 2019 (last updated February 28, 2024)
A hidden RPC service issue was found with Pulse Secure Pulse Connect Secure 8.3RX before 8.3R2 and 8.1RX before 8.1R12.
0
Attacker Value
Unknown
CVE-2018-20808
Disclosure Date: June 28, 2019 (last updated February 28, 2024)
An XSS issue has been found with rd.cgi in Pulse Secure Pulse Connect Secure 8.3RX before 8.3R3 due to improper header sanitization. This is not applicable to 8.1RX.
0