Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hcxw-prp6-q3jq

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 10

Описание

Pulse Connect Secure 9.0R3/9.1R1 and higher is vulnerable to an authentication bypass vulnerability exposed by the Windows File Share Browser and Pulse Secure Collaboration features of Pulse Connect Secure that can allow an unauthenticated user to perform remote arbitrary code execution on the Pulse Connect Secure gateway. This vulnerability has been exploited in the wild.

Pulse Connect Secure 9.0R3/9.1R1 and higher is vulnerable to an authentication bypass vulnerability exposed by the Windows File Share Browser and Pulse Secure Collaboration features of Pulse Connect Secure that can allow an unauthenticated user to perform remote arbitrary code execution on the Pulse Connect Secure gateway. This vulnerability has been exploited in the wild.

EPSS

Процентиль: 100%
0.93485
Критический

10 Critical

CVSS3

Дефекты

CWE-287
CWE-416

Связанные уязвимости

CVSS3: 10
nvd
почти 5 лет назад

Pulse Connect Secure 9.0R3/9.1R1 and higher is vulnerable to an authentication bypass vulnerability exposed by the Windows File Share Browser and Pulse Secure Collaboration features of Pulse Connect Secure that can allow an unauthenticated user to perform remote arbitrary code execution on the Pulse Connect Secure gateway. This vulnerability has been exploited in the wild.

CVSS3: 10
fstec
почти 5 лет назад

Уязвимость VPN-шлюза корпоративных сетей Pulse Connect Secure, связанная с ошибками аутентификации, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 100%
0.93485
Критический

10 Critical

CVSS3

Дефекты

CWE-287
CWE-416