Pulse Policy Secure
Vendor:
First CVE: Aug 29, 2017 · Active for 8 years
31
Total CVEs
More Total CVEs than 97% of tracked products
7.8
Avg CVEs / Year
Higher CVE frequency than 95% of tracked products
7.2
Avg CVSS
Higher Avg CVSS than 48% of tracked products
6.5%
KEV Rate
Higher KEV Rate than 98% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Pulse Policy Secure over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 29, 2017
8 years ago
Most Recent CVE
Oct 28, 2020
2,099 days ago
CVE Severity & Scoring
Pulse Policy Secure31 CVEs
42%
42%
16%
All CVEs353,173 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (3.2%)
Network29 (93.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (3.2%)
Attack Complexity
Low29 (93.5%)
High2 (6.5%)
Unknown0 (0.0%)
User Interaction
None22 (71.0%)
Unknown0 (0.0%)
Required9 (29.0%)
Privileges Required
Low4 (12.9%)
High8 (25.8%)
None19 (61.3%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (31 CVEs).
31 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-11539HIGH In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1RX before 8.1R15.1 and Pulse Policy Secure version 9.0RX befo | Apr 26, 2019 | 7.2 | 97 | YES | YES |
CVE-2019-11477HIGH Jonathan Looney discovered that the TCP_SKB_CB(skb)->tcp_gso_segs value was subject to an integer overflow in the Linux kernel when handling TCP Selective Acknowledgments (SACKs). | Jun 19, 2019 | 7.5 | 78 | NO | NO |
CVE-2020-8218HIGH A code injection vulnerability exists in Pulse Connect Secure <9.1R8 that allows an attacker to crafted a URI to perform an arbitrary code execution via the admin web interface. | Jul 30, 2020 | 7.2 | 77 | YES | NO |
CVE-2019-11478HIGH Jonathan Looney discovered that the TCP retransmission queue implementation in tcp_fragment in the Linux kernel could be fragmented when handling certain TCP Selective Acknowledgme | Jun 19, 2019 | 7.5 | 76 | NO | NO |
CVE-2019-11542HIGH In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1RX before 8.1R15.1 and Pulse Policy Secure version 9.0RX befo | Apr 26, 2019 | 7.2 | 60 | NO | NO |
CVE-2019-11540CRITICAL In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4 and 8.3RX before 8.3R7.1 and Pulse Policy Secure version 9.0RX before 9.0R3.2 and 5.4RX before 5.4R7.1, an unauthe | Apr 26, 2019 | 9.8 | 35 | NO | NO |
CVE-2018-6320CRITICAL A vulnerability has been discovered in login.cgi in Pulse Secure Pulse Connect Secure (PCS) 8.1RX before 8.1R12 and 8.3RX before 8.3R2 and Pulse Policy Secure (PPS) 5.2RX before 5. | Sep 6, 2018 | 9.8 | 33 | NO | NO |
CVE-2020-11581HIGH An issue was discovered in Pulse Secure Pulse Connect Secure (PCS) through 2020-04-06. The applet in tncc.jar, executed on macOS, Linux, and Solaris clients when a Host Checker pol | Apr 6, 2020 | 8.1 | 30 | NO | NO |
CVE-2018-20810CRITICAL Session data between cluster nodes during cluster synchronization is not properly encrypted in Pulse Secure Pulse Connect Secure (PCS) 8.3RX before 8.3R2 and Pulse Policy Secure (P | Jun 28, 2019 | 9.8 | 30 | NO | NO |
CVE-2019-11509HIGH In Pulse Secure Pulse Connect Secure (PCS) before 8.1R15.1, 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4 and Pulse Policy Secure (PPS) before 5.1R15.1, 5.2 befor | Jun 3, 2019 | 8.8 | 30 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (31 CVEs).
CISA KEV
2 CVEs
6.5% of CVEs· 98th percentile
Metasploit
1 CVE
3.2% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
3.2% of CVEs· 85th percentile
Social Chatter
Signals from CVEs in this product scope (31 CVEs).
Media Mentions
Signals from CVEs in this product scope (31 CVEs).
Top CNAs Publishing CVEs For Pulse Policy Secure
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 9.0rx | 3 | 7.7 | 25.8% | 0 | 0 |
| 9.0r3.1 | 3 | 7.7 | 25.8% | 0 | 0 |
| 9.0r3 | 3 | 7.7 | 25.8% | 0 | 0 |
| 9.0r2.1 | 3 | 7.7 | 25.8% | 0 | 0 |
| 9.0r2 | 3 | 7.7 | 25.8% | 0 | 0 |
| 9.0r1 | 3 | 7.7 | 25.8% | 0 | 0 |
| 5.4rx | 6 | 7.7 | 30.3% | 1 | 1 |
| 5.4r7 | 4 | 7.6 | 44.0% | 1 | 1 |
| 5.4r6.1 | 4 | 7.6 | 44.0% | 1 | 1 |
| 5.4r6 | 4 | 7.6 | 44.0% | 1 | 1 |
| 5.4r5.2 | 4 | 7.6 | 44.0% | 1 | 1 |
| 5.4r5 | 4 | 7.6 | 44.0% | 1 | 1 |
| 5.4r4 | 4 | 7.6 | 44.0% | 1 | 1 |
| 5.4r3 | 5 | 7.3 | 35.5% | 1 | 1 |
| 5.4r2.1 | 5 | 7.3 | 35.5% | 1 | 1 |
| 5.4r2 | 6 | 7.7 | 30.3% | 1 | 1 |
| 5.4r1 | 6 | 7.7 | 30.3% | 1 | 1 |
| 5.4 | 4 | 8.3 | 5.7% | 0 | 0 |
| 5.3rx | 2 | 7.2 | 82.4% | 1 | 1 |
| 5.3r9.0 | 2 | 7.2 | 82.4% | 1 | 1 |