vulnerability
Pulse Secure Pulse Connect Secure: SA45476 - Client Side Desync Attack (Informational)
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 5 | (AV:N/AC:M/Au:S/C:P/I:P/A:N) | Feb 14, 2023 | May 21, 2024 | Mar 26, 2026 |
Severity
5
CVSS
(AV:N/AC:M/Au:S/C:P/I:P/A:N)
Published
Feb 14, 2023
Added
May 21, 2024
Modified
Mar 26, 2026
Description
The type of attack in this instance is a Client-Side Desync (CSD) Attack that requires an authenticated user and requires full control over an authenticated session. This is possible between a client machine and the VPN (Pulse Connect Secure) server. The vulnerability affects the Pulse Collaboration feature.
Solution
pulse-secure-pulse-connect-secure-upgrade-9_1r16
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.