Pulse Secure Desktop Client
Vendor:
First CVE: Sep 6, 2018 · Active for 7 years
18
Total CVEs
More Total CVEs than 94% of tracked products
6.0
Avg CVEs / Year
Higher CVE frequency than 91% of tracked products
7.0
Avg CVSS
Higher Avg CVSS than 44% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Pulse Secure Desktop Client over time
Volume of CVEsAvg CVSS Base Score
First CVE
Sep 6, 2018
7 years ago
Most Recent CVE
Oct 28, 2020
2,099 days ago
CVE Severity & Scoring
Pulse Secure Desktop Client18 CVEs
39%
56%
All CVEs353,240 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local9 (50.0%)
Network8 (44.4%)
Unknown0 (0.0%)
Physical1 (5.6%)
Adjacent Network0 (0.0%)
Attack Complexity
Low15 (83.3%)
High3 (16.7%)
Unknown0 (0.0%)
User Interaction
None13 (72.2%)
Unknown0 (0.0%)
Required5 (27.8%)
Privileges Required
Low10 (55.6%)
High1 (5.6%)
None7 (38.9%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (18 CVEs).
18 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-11213HIGH In Pulse Secure Pulse Desktop Client and Network Connect, an attacker could access session tokens to replay and spoof sessions, and as a result, gain unauthorized access as an end | Apr 12, 2019 | 8.1 | 27 | NO | NO |
CVE-2020-8254HIGH A vulnerability in the Pulse Secure Desktop Client < 9.1R9 has Remote Code Execution (RCE) if users can be convinced to connect to a malicious server. This vulnerability only affec | Oct 28, 2020 | 8.8 | 26 | NO | NO |
CVE-2020-8250HIGH A vulnerability in the Pulse Secure Desktop Client (Linux) < 9.1R9 could allow local attackers to escalate privilege. | Oct 28, 2020 | 7.8 | 25 | NO | NO |
CVE-2020-8249HIGH A vulnerability in the Pulse Secure Desktop Client (Linux) < 9.1R9 could allow local attackers to perform buffer overflow. | Oct 28, 2020 | 7.8 | 25 | NO | NO |
CVE-2020-8241HIGH A vulnerability in the Pulse Secure Desktop Client < 9.1R9 could allow the attacker to perform a MITM Attack if end users are convinced to connect to a malicious server. | Oct 28, 2020 | 7.5 | 25 | NO | NO |
CVE-2020-8240HIGH A vulnerability in the Pulse Secure Desktop Client < 9.1R9 allows a restricted user on an endpoint machine can use system-level privileges if the Embedded Browser is configured wit | Oct 28, 2020 | 7.8 | 25 | NO | NO |
CVE-2018-15865HIGH The Pulse Secure Desktop (macOS) has a Privilege Escalation Vulnerability. | Sep 6, 2018 | 7.8 | 25 | NO | NO |
CVE-2020-8248HIGH A vulnerability in the Pulse Secure Desktop Client (Linux) < 9.1R9 could allow local attackers to escalate privilege. | Oct 28, 2020 | 7.8 | 24 | NO | NO |
CVE-2020-8239CRITICAL A vulnerability in the Pulse Secure Desktop Client < 9.1R9 is vulnerable to the client registry privilege escalation attack. This fix also requires Server Side Upgrade due to Stand | Oct 28, 2020 | 9.8 | 24 | NO | NO |
CVE-2018-20812HIGH An information exposure issue where IPv6 DNS traffic would be sent outside of the VPN tunnel (when Traffic Enforcement was enabled) exists in Pulse Secure Pulse Secure Desktop 9.0R | Jun 28, 2019 | 7.5 | 24 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (18 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (18 CVEs).
Media Mentions
Signals from CVEs in this product scope (18 CVEs).
Top CNAs Publishing CVEs For Pulse Secure Desktop Client
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 9.1 | 11 | 7.3 | 1.1% | 0 | 0 |
| 9.0r1 | 3 | 5.9 | 0.3% | 0 | 0 |
| 9.0 | 2 | 7.2 | 0.9% | 0 | 0 |
| 5.3rx | 3 | 5.9 | 0.3% | 0 | 0 |
| 5.3r6 | 1 | 5.5 | 0.9% | 0 | 0 |
| 5.3r5.2 | 2 | 6.7 | 0.6% | 0 | 0 |
| 5.3r5 | 2 | 6.7 | 0.6% | 0 | 0 |
| 5.3r4.2 | 5 | 6.2 | 0.4% | 0 | 0 |
| 5.3r4.1 | 5 | 6.2 | 0.4% | 0 | 0 |
| 5.3r4 | 5 | 6.2 | 0.4% | 0 | 0 |
| 5.3r3 | 5 | 6.2 | 0.4% | 0 | 0 |
| 5.3r2 | 5 | 6.2 | 0.4% | 0 | 0 |
| 5.3r1.1 | 5 | 6.2 | 0.4% | 0 | 0 |
| 5.3r1 | 5 | 6.2 | 0.4% | 0 | 0 |
| 5.3 | 2 | 7.3 | 1.0% | 0 | 0 |
| 5.1rx | 1 | 7.8 | 0.3% | 0 | 0 |
| 5.1r9.1 | 1 | 7.8 | 0.3% | 0 | 0 |
| 5.1r9.0 | 1 | 7.8 | 0.3% | 0 | 0 |
| 5.1r8.0 | 1 | 7.8 | 0.3% | 0 | 0 |
| 5.1r7.0 | 1 | 7.8 | 0.3% | 0 | 0 |