Pulse Secure Desktop Client

Vendor:

First CVE: Sep 6, 2018 · Active for 7 years

18
Total CVEs
More Total CVEs than 94% of tracked products
6.0
Avg CVEs / Year
Higher CVE frequency than 91% of tracked products
7.0
Avg CVSS
Higher Avg CVSS than 44% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Pulse Secure Desktop Client over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 6, 2018
7 years ago
Most Recent CVE
Oct 28, 2020
2,099 days ago

CVE Severity & Scoring

Pulse Secure Desktop Client18 CVEs
All CVEs353,240 CVEs
MediumHighCritical
Attack Vector
Local9 (50.0%)
Network8 (44.4%)
Unknown0 (0.0%)
Physical1 (5.6%)
Adjacent Network0 (0.0%)
Attack Complexity
Low15 (83.3%)
High3 (16.7%)
Unknown0 (0.0%)
User Interaction
None13 (72.2%)
Unknown0 (0.0%)
Required5 (27.8%)
Privileges Required
Low10 (55.6%)
High1 (5.6%)
None7 (38.9%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (18 CVEs).

18 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
In Pulse Secure Pulse Desktop Client and Network Connect, an attacker could access session tokens to replay and spoof sessions, and as a result, gain unauthorized access as an end
Apr 12, 20198.127NONO
A vulnerability in the Pulse Secure Desktop Client < 9.1R9 has Remote Code Execution (RCE) if users can be convinced to connect to a malicious server. This vulnerability only affec
Oct 28, 20208.826NONO
A vulnerability in the Pulse Secure Desktop Client (Linux) < 9.1R9 could allow local attackers to escalate privilege.
Oct 28, 20207.825NONO
A vulnerability in the Pulse Secure Desktop Client (Linux) < 9.1R9 could allow local attackers to perform buffer overflow.
Oct 28, 20207.825NONO
A vulnerability in the Pulse Secure Desktop Client < 9.1R9 could allow the attacker to perform a MITM Attack if end users are convinced to connect to a malicious server.
Oct 28, 20207.525NONO
A vulnerability in the Pulse Secure Desktop Client < 9.1R9 allows a restricted user on an endpoint machine can use system-level privileges if the Embedded Browser is configured wit
Oct 28, 20207.825NONO
The Pulse Secure Desktop (macOS) has a Privilege Escalation Vulnerability.
Sep 6, 20187.825NONO
A vulnerability in the Pulse Secure Desktop Client (Linux) < 9.1R9 could allow local attackers to escalate privilege.
Oct 28, 20207.824NONO
A vulnerability in the Pulse Secure Desktop Client < 9.1R9 is vulnerable to the client registry privilege escalation attack. This fix also requires Server Side Upgrade due to Stand
Oct 28, 20209.824NONO
An information exposure issue where IPv6 DNS traffic would be sent outside of the VPN tunnel (when Traffic Enforcement was enabled) exists in Pulse Secure Pulse Secure Desktop 9.0R
Jun 28, 20197.524NONO

Exploit Exposure

Signals from CVEs in this product scope (18 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (18 CVEs).

Media Mentions

Signals from CVEs in this product scope (18 CVEs).

Top CNAs Publishing CVEs For Pulse Secure Desktop Client

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
9.1117.31.1%00
9.0r135.90.3%00
9.027.20.9%00
5.3rx35.90.3%00
5.3r615.50.9%00
5.3r5.226.70.6%00
5.3r526.70.6%00
5.3r4.256.20.4%00
5.3r4.156.20.4%00
5.3r456.20.4%00
5.3r356.20.4%00
5.3r256.20.4%00
5.3r1.156.20.4%00
5.3r156.20.4%00
5.327.31.0%00
5.1rx17.80.3%00
5.1r9.117.80.3%00
5.1r9.017.80.3%00
5.1r8.017.80.3%00
5.1r7.017.80.3%00