Pulse Connect Secure
Vendor:
First CVE: Apr 12, 2016 · Active for 10 years
57
Total CVEs
More Total CVEs than 99% of tracked products
8.1
Avg CVEs / Year
Higher CVE frequency than 95% of tracked products
7.0
Avg CVSS
Higher Avg CVSS than 45% of tracked products
1.8%
KEV Rate
Higher KEV Rate than 98% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Pulse Connect Secure over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 12, 2016
10 years ago
Most Recent CVE
Sep 30, 2022
1,397 days ago
CVE Severity & Scoring
Pulse Connect Secure57 CVEs
44%
47%
9%
All CVEs353,173 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local7 (12.3%)
Network49 (86.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (1.8%)
Attack Complexity
Low54 (94.7%)
High3 (5.3%)
Unknown0 (0.0%)
User Interaction
None34 (59.6%)
Unknown0 (0.0%)
Required23 (40.4%)
Privileges Required
Low7 (12.3%)
High17 (29.8%)
None33 (57.9%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (57 CVEs).
57 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-22900HIGH A vulnerability allowed multiple unrestricted uploads in Pulse Connect Secure before 9.1R11.4 that could lead to an authenticated administrator to perform a file write via a malici | May 27, 2021 | 7.2 | 70 | YES | NO |
CVE-2021-22908HIGH A buffer overflow vulnerability exists in Windows File Resource Profiles in 9.X allows a remote authenticated user with privileges to browse SMB shares to execute arbitrary code as | May 27, 2021 | 8.8 | 66 | NO | NO |
CVE-2019-11542HIGH In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1RX before 8.1R15.1 and Pulse Policy Secure version 9.0RX befo | Apr 26, 2019 | 7.2 | 60 | NO | NO |
CVE-2022-21826MEDIUM Pulse Secure version 9.115 and below may be susceptible to client-side http request smuggling, When the application receives a POST request, it ignores the request's Content-Length | Sep 30, 2022 | 5.4 | 35 | NO | NO |
CVE-2019-11540CRITICAL In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4 and 8.3RX before 8.3R7.1 and Pulse Policy Secure version 9.0RX before 9.0R3.2 and 5.4RX before 5.4R7.1, an unauthe | Apr 26, 2019 | 9.8 | 35 | NO | NO |
CVE-2018-18284HIGH Artifex Ghostscript 9.25 and earlier allows attackers to bypass a sandbox protection mechanism via vectors involving the 1Policy operator. | Oct 19, 2018 | 8.6 | 35 | NO | NO |
CVE-2018-6320CRITICAL A vulnerability has been discovered in login.cgi in Pulse Secure Pulse Connect Secure (PCS) 8.1RX before 8.1R12 and 8.3RX before 8.3R2 and Pulse Policy Secure (PPS) 5.2RX before 5. | Sep 6, 2018 | 9.8 | 33 | NO | NO |
CVE-2019-11508HIGH In Pulse Secure Pulse Connect Secure (PCS) before 8.1R15.1, 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an authenticated attacker (via the admin web interface) | May 8, 2019 | 7.2 | 31 | NO | NO |
CVE-2016-4787CRITICAL Pulse Connect Secure (PCS) 8.2 before 8.2r1, 8.1 before 8.1r2, 8.0 before 8.0r10, and 7.4 before 7.4r13.4 allow remote attackers to read sensitive system authentication files in an | May 26, 2016 | 10.0 | 31 | NO | NO |
CVE-2020-11581HIGH An issue was discovered in Pulse Secure Pulse Connect Secure (PCS) through 2020-04-06. The applet in tncc.jar, executed on macOS, Linux, and Solaris clients when a Host Checker pol | Apr 6, 2020 | 8.1 | 30 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (57 CVEs).
CISA KEV
1 CVE
1.8% of CVEs· 98th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (57 CVEs).
Media Mentions
Signals from CVEs in this product scope (57 CVEs).
Top CNAs Publishing CVEs For Pulse Connect Secure
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 9.0rx | 5 | 7.9 | 30.2% | 0 | 0 |
| 9.0r3.2 | 4 | 7.7 | 20.4% | 0 | 0 |
| 9.0r3.1 | 4 | 7.7 | 20.4% | 0 | 0 |
| 9.0r3 | 4 | 7.7 | 20.4% | 0 | 0 |
| 9.0r2.1 | 4 | 7.7 | 20.4% | 0 | 0 |
| 9.0r2 | 4 | 7.7 | 20.4% | 0 | 0 |
| 9.0r1 | 4 | 7.7 | 20.4% | 0 | 0 |
| 8.3rx | 6 | 7.8 | 14.5% | 0 | 0 |
| 8.3r1.0 | 4 | 7.5 | 0.7% | 0 | 0 |
| 8.2rx | 2 | 7.3 | 35.0% | 0 | 0 |
| 8.2r7.1 | 2 | 7.3 | 35.0% | 0 | 0 |
| 8.2r7.0 | 2 | 7.3 | 35.0% | 0 | 0 |
| 8.2r6.0 | 2 | 7.3 | 35.0% | 0 | 0 |
| 8.2r5.1 | 2 | 7.3 | 35.0% | 0 | 0 |
| 8.2r5.0 | 3 | 7.8 | 23.8% | 0 | 0 |
| 8.2r4.1 | 3 | 7.8 | 23.8% | 0 | 0 |
| 8.2r4.0 | 3 | 7.8 | 23.8% | 0 | 0 |
| 8.2r3.1 | 3 | 7.8 | 23.8% | 0 | 0 |
| 8.2r3.0 | 3 | 7.8 | 23.8% | 0 | 0 |
| 8.2r2.0 | 3 | 7.8 | 23.8% | 0 | 0 |