Pulse Policy Secure

Vendor:

First CVE: Aug 29, 2017 · Active for 8 years

31
Total CVEs
More Total CVEs than 97% of tracked products
7.8
Avg CVEs / Year
Higher CVE frequency than 95% of tracked products
7.2
Avg CVSS
Higher Avg CVSS than 48% of tracked products
6.5%
KEV Rate
Higher KEV Rate than 98% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Pulse Policy Secure over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 29, 2017
8 years ago
Most Recent CVE
Oct 28, 2020
2,099 days ago

CVE Severity & Scoring

Pulse Policy Secure31 CVEs
All CVEs353,173 CVEs
MediumHighCritical
Attack Vector
Local1 (3.2%)
Network29 (93.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (3.2%)
Attack Complexity
Low29 (93.5%)
High2 (6.5%)
Unknown0 (0.0%)
User Interaction
None22 (71.0%)
Unknown0 (0.0%)
Required9 (29.0%)
Privileges Required
Low4 (12.9%)
High8 (25.8%)
None19 (61.3%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (31 CVEs).

31 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1RX before 8.1R15.1 and Pulse Policy Secure version 9.0RX befo
Apr 26, 20197.297YESYES
Jonathan Looney discovered that the TCP_SKB_CB(skb)->tcp_gso_segs value was subject to an integer overflow in the Linux kernel when handling TCP Selective Acknowledgments (SACKs).
Jun 19, 20197.578NONO
A code injection vulnerability exists in Pulse Connect Secure <9.1R8 that allows an attacker to crafted a URI to perform an arbitrary code execution via the admin web interface.
Jul 30, 20207.277YESNO
Jonathan Looney discovered that the TCP retransmission queue implementation in tcp_fragment in the Linux kernel could be fragmented when handling certain TCP Selective Acknowledgme
Jun 19, 20197.576NONO
In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1RX before 8.1R15.1 and Pulse Policy Secure version 9.0RX befo
Apr 26, 20197.260NONO
In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4 and 8.3RX before 8.3R7.1 and Pulse Policy Secure version 9.0RX before 9.0R3.2 and 5.4RX before 5.4R7.1, an unauthe
Apr 26, 20199.835NONO
A vulnerability has been discovered in login.cgi in Pulse Secure Pulse Connect Secure (PCS) 8.1RX before 8.1R12 and 8.3RX before 8.3R2 and Pulse Policy Secure (PPS) 5.2RX before 5.
Sep 6, 20189.833NONO
An issue was discovered in Pulse Secure Pulse Connect Secure (PCS) through 2020-04-06. The applet in tncc.jar, executed on macOS, Linux, and Solaris clients when a Host Checker pol
Apr 6, 20208.130NONO
Session data between cluster nodes during cluster synchronization is not properly encrypted in Pulse Secure Pulse Connect Secure (PCS) 8.3RX before 8.3R2 and Pulse Policy Secure (P
Jun 28, 20199.830NONO
In Pulse Secure Pulse Connect Secure (PCS) before 8.1R15.1, 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4 and Pulse Policy Secure (PPS) before 5.1R15.1, 5.2 befor
Jun 3, 20198.830NONO

Exploit Exposure

Signals from CVEs in this product scope (31 CVEs).

CISA KEV
2 CVEs
6.5% of CVEs· 98th percentile
Metasploit
1 CVE
3.2% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
3.2% of CVEs· 85th percentile

Social Chatter

Signals from CVEs in this product scope (31 CVEs).

Media Mentions

Signals from CVEs in this product scope (31 CVEs).

Top CNAs Publishing CVEs For Pulse Policy Secure

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
9.0rx37.725.8%00
9.0r3.137.725.8%00
9.0r337.725.8%00
9.0r2.137.725.8%00
9.0r237.725.8%00
9.0r137.725.8%00
5.4rx67.730.3%11
5.4r747.644.0%11
5.4r6.147.644.0%11
5.4r647.644.0%11
5.4r5.247.644.0%11
5.4r547.644.0%11
5.4r447.644.0%11
5.4r357.335.5%11
5.4r2.157.335.5%11
5.4r267.730.3%11
5.4r167.730.3%11
5.448.35.7%00
5.3rx27.282.4%11
5.3r9.027.282.4%11