Pulse Connect Secure

Vendor:

First CVE: Apr 12, 2016 · Active for 10 years

57
Total CVEs
More Total CVEs than 99% of tracked products
8.1
Avg CVEs / Year
Higher CVE frequency than 95% of tracked products
7.0
Avg CVSS
Higher Avg CVSS than 45% of tracked products
1.8%
KEV Rate
Higher KEV Rate than 98% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Pulse Connect Secure over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 12, 2016
10 years ago
Most Recent CVE
Sep 30, 2022
1,397 days ago

CVE Severity & Scoring

Pulse Connect Secure57 CVEs
All CVEs353,173 CVEs
MediumHighCritical
Attack Vector
Local7 (12.3%)
Network49 (86.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (1.8%)
Attack Complexity
Low54 (94.7%)
High3 (5.3%)
Unknown0 (0.0%)
User Interaction
None34 (59.6%)
Unknown0 (0.0%)
Required23 (40.4%)
Privileges Required
Low7 (12.3%)
High17 (29.8%)
None33 (57.9%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (57 CVEs).

57 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A vulnerability allowed multiple unrestricted uploads in Pulse Connect Secure before 9.1R11.4 that could lead to an authenticated administrator to perform a file write via a malici
May 27, 20217.270YESNO
A buffer overflow vulnerability exists in Windows File Resource Profiles in 9.X allows a remote authenticated user with privileges to browse SMB shares to execute arbitrary code as
May 27, 20218.866NONO
In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1RX before 8.1R15.1 and Pulse Policy Secure version 9.0RX befo
Apr 26, 20197.260NONO
Pulse Secure version 9.115 and below may be susceptible to client-side http request smuggling, When the application receives a POST request, it ignores the request's Content-Length
Sep 30, 20225.435NONO
In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4 and 8.3RX before 8.3R7.1 and Pulse Policy Secure version 9.0RX before 9.0R3.2 and 5.4RX before 5.4R7.1, an unauthe
Apr 26, 20199.835NONO
Artifex Ghostscript 9.25 and earlier allows attackers to bypass a sandbox protection mechanism via vectors involving the 1Policy operator.
Oct 19, 20188.635NONO
A vulnerability has been discovered in login.cgi in Pulse Secure Pulse Connect Secure (PCS) 8.1RX before 8.1R12 and 8.3RX before 8.3R2 and Pulse Policy Secure (PPS) 5.2RX before 5.
Sep 6, 20189.833NONO
In Pulse Secure Pulse Connect Secure (PCS) before 8.1R15.1, 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an authenticated attacker (via the admin web interface)
May 8, 20197.231NONO
Pulse Connect Secure (PCS) 8.2 before 8.2r1, 8.1 before 8.1r2, 8.0 before 8.0r10, and 7.4 before 7.4r13.4 allow remote attackers to read sensitive system authentication files in an
May 26, 201610.031NONO
An issue was discovered in Pulse Secure Pulse Connect Secure (PCS) through 2020-04-06. The applet in tncc.jar, executed on macOS, Linux, and Solaris clients when a Host Checker pol
Apr 6, 20208.130NONO

Exploit Exposure

Signals from CVEs in this product scope (57 CVEs).

CISA KEV
1 CVE
1.8% of CVEs· 98th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (57 CVEs).

Media Mentions

Signals from CVEs in this product scope (57 CVEs).

Top CNAs Publishing CVEs For Pulse Connect Secure

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
9.0rx57.930.2%00
9.0r3.247.720.4%00
9.0r3.147.720.4%00
9.0r347.720.4%00
9.0r2.147.720.4%00
9.0r247.720.4%00
9.0r147.720.4%00
8.3rx67.814.5%00
8.3r1.047.50.7%00
8.2rx27.335.0%00
8.2r7.127.335.0%00
8.2r7.027.335.0%00
8.2r6.027.335.0%00
8.2r5.127.335.0%00
8.2r5.037.823.8%00
8.2r4.137.823.8%00
8.2r4.037.823.8%00
8.2r3.137.823.8%00
8.2r3.037.823.8%00
8.2r2.037.823.8%00