vulnerability

Pulse Secure Pulse Connect Secure: SA45476 - Client Side Desync Attack (Informational)

Severity
5
CVSS
(AV:N/AC:M/Au:S/C:P/I:P/A:N)
Published
Feb 14, 2023
Added
May 21, 2024
Modified
Mar 26, 2026

Description

The type of attack in this instance is a Client-Side Desync (CSD) Attack that requires an authenticated user and requires full control over an authenticated session. This is possible between a client machine and the VPN (Pulse Connect Secure) server. The vulnerability affects the Pulse Collaboration feature.

Solution

pulse-secure-pulse-connect-secure-upgrade-9_1r16
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.