Pulsesecure's vulnerability footprint is anchored in a focused set of remote-access and network security appliances—Pulse Connect Secure, Pulse Policy Secure, and its desktop client products—that serve as gateways and enforcement points for enterprise access control, giving vulnerabilities in this portfolio outsized impact on defended perimeters. The recurring weakness classes, including cross-site scripting, path traversal, buffer overflows, and sensitive information exposure, reflect the input-handling and access-control demands of gateway and policy-enforcement appliances. A meaningful share of the vendor's disclosures reach serious severity; the exposure pattern suggests that defenders should treat this vendor's advisories as high-priority, particularly for internet-reachable instances and VPN concentrators. Defenders should maintain close tracking of Pulsesecure release schedules and apply patches to remote-access appliances with urgency, as compromise of these products can grant attackers deep network reach; live exploitation activity, severity breakdown, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pulsesecure over time
Signals from CVEs in this vendor scope (93 CVEs).
93 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-11539HIGH In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1RX before 8.1R15.1 and Pulse Policy Secure version 9.0RX befo | Apr 26, 2019 | 7.2 | 97 | YES | YES |
CVE-2019-11477HIGH Jonathan Looney discovered that the TCP_SKB_CB(skb)->tcp_gso_segs value was subject to an integer overflow in the Linux kernel when handling TCP Selective Acknowledgments (SACKs). | Jun 19, 2019 | 7.5 | 78 | NO | NO |
CVE-2020-8218HIGH A code injection vulnerability exists in Pulse Connect Secure <9.1R8 that allows an attacker to crafted a URI to perform an arbitrary code execution via the admin web interface. | Jul 30, 2020 | 7.2 | 77 | YES | NO |
CVE-2019-11478HIGH Jonathan Looney discovered that the TCP retransmission queue implementation in tcp_fragment in the Linux kernel could be fragmented when handling certain TCP Selective Acknowledgme | Jun 19, 2019 | 7.5 | 76 | NO | NO |
CVE-2016-0800MEDIUM The SSLv2 protocol, as used in OpenSSL before 1.0.1s and 1.0.2 before 1.0.2g and other products, requires a server to send a ServerVerify message before establishing that a client | Mar 1, 2016 | 5.9 | 75 | NO | YES |
CVE-2021-22900HIGH A vulnerability allowed multiple unrestricted uploads in Pulse Connect Secure before 9.1R11.4 that could lead to an authenticated administrator to perform a file write via a malici | May 27, 2021 | 7.2 | 70 | YES | NO |
CVE-2021-22908HIGH A buffer overflow vulnerability exists in Windows File Resource Profiles in 9.X allows a remote authenticated user with privileges to browse SMB shares to execute arbitrary code as | May 27, 2021 | 8.8 | 66 | NO | NO |
CVE-2019-11542HIGH In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1RX before 8.1R15.1 and Pulse Policy Secure version 9.0RX befo | Apr 26, 2019 | 7.2 | 60 | NO | NO |
CVE-2016-0799CRITICAL The fmtstr function in crypto/bio/b_print.c in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g improperly calculates string lengths, which allows remote attackers to cause a de | Mar 3, 2016 | 9.8 | 49 | NO | NO |
CVE-2022-21826MEDIUM Pulse Secure version 9.115 and below may be susceptible to client-side http request smuggling, When the application receives a POST request, it ignores the request's Content-Length | Sep 30, 2022 | 5.4 | 35 | NO | NO |
Signals from CVEs in this vendor scope (93 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pulsesecure.
Media articles that mention a CVE ID that affects a product developed by Pulsesecure — matched by CVE ID, not by vendor name.