vulnerability
Pulse Secure Pulse Connect Secure: CVE-2018-6320: Multiple vulnerabilities resolved in Pulse Connect Secure / Pulse Policy Secure / Pulse Secure Desktop 9.0R1/9.0R2 (SA43877)
Severity | CVSS | Published | Added | Modified |
---|---|---|---|---|
8 | (AV:N/AC:L/Au:N/C:P/I:P/A:P) | Sep 6, 2018 | Oct 28, 2020 | Feb 15, 2024 |
Severity
8
CVSS
(AV:N/AC:L/Au:N/C:P/I:P/A:P)
Published
Sep 6, 2018
Added
Oct 28, 2020
Modified
Feb 15, 2024
Description
A vulnerability has been discovered in login.cgi in Pulse Secure Pulse Connect Secure (PCS) 8.1RX before 8.1R12 and 8.3RX before 8.3R2 and Pulse Policy Secure (PPS) 5.2RX before 5.2R9 and 5.4RX before 5.4R2 wherein an http(s) Host header received from the browser is trusted without validation.
Solution(s)
pulse-secure-pulse-connect-secure-upgrade-8_1r14pulse-secure-pulse-connect-secure-upgrade-8_3r6pulse-secure-pulse-connect-secure-upgrade-9_0r1

NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.