SB2019062818 - Multiple vulnerabilities in Pulse Connect Secure
Published: June 28, 2019 Updated: August 8, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 4 secuirty vulnerabilities.
1) Cross-site scripting (CVE-ID: CVE-2018-20807)
The vulnerability allows a remote non-authenticated attacker to read and manipulate data.
An XSS issue has been found in welcome.cgi in Pulse Secure Pulse Connect Secure (PCS) 8.1.x before 8.1R12, 8.2.x before 8.2R9, and 8.3.x before 8.3R3 due to one of the URL parameters not being sanitized properly.
2) Cross-site scripting (CVE-ID: CVE-2018-20808)
The vulnerability allows a remote non-authenticated attacker to read and manipulate data.
An XSS issue has been found with rd.cgi in Pulse Secure Pulse Connect Secure 8.3RX before 8.3R3 due to improper header sanitization. This is not applicable to 8.1RX.
3) Information disclosure (CVE-ID: CVE-2018-20811)
The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.
A hidden RPC service issue was found with Pulse Secure Pulse Connect Secure 8.3RX before 8.3R2 and 8.1RX before 8.1R12.
4) Input validation error (CVE-ID: CVE-2018-20813)
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
An input validation issue has been found with login_meeting.cgi in Pulse Secure Pulse Connect Secure 8.3RX before 8.3R2.
Remediation
Install update from vendor's website.