Vulnerabilities > Pulsesecure

DATE CVE VULNERABILITY TITLE RISK
2020-10-28 CVE-2020-8248 Unspecified vulnerability in Pulsesecure Pulse Secure Desktop Client 9.1
A vulnerability in the Pulse Secure Desktop Client (Linux) < 9.1R9 could allow local attackers to escalate privilege.
local
low complexity
pulsesecure
7.8
2020-10-28 CVE-2020-8241 Unspecified vulnerability in Pulsesecure Pulse Secure Desktop Client 9.1
A vulnerability in the Pulse Secure Desktop Client < 9.1R9 could allow the attacker to perform a MITM Attack if end users are convinced to connect to a malicious server.
network
high complexity
pulsesecure
7.5
2020-10-28 CVE-2020-8240 Unspecified vulnerability in Pulsesecure Pulse Secure Desktop Client
A vulnerability in the Pulse Secure Desktop Client < 9.1R9 allows a restricted user on an endpoint machine can use system-level privileges if the Embedded Browser is configured with Credential Provider.
local
low complexity
pulsesecure
7.8
2020-10-28 CVE-2020-8239 Unspecified vulnerability in Pulsesecure Pulse Secure Desktop Client 9.1
A vulnerability in the Pulse Secure Desktop Client < 9.1R9 is vulnerable to the client registry privilege escalation attack.
network
low complexity
pulsesecure
critical
9.8
2020-10-27 CVE-2020-8956 Weak Password Requirements vulnerability in Pulsesecure Pulse Secure Desktop
Pulse Secure Desktop Client 9.0Rx before 9.0R5 and 9.1Rx before 9.1R4 on Windows reveals users' passwords if Save Settings is enabled.
local
low complexity
pulsesecure CWE-521
3.3
2020-10-27 CVE-2020-15352 XXE vulnerability in multiple products
An XML external entity (XXE) vulnerability in Pulse Connect Secure (PCS) before 9.1R9 and Pulse Policy Secure (PPS) before 9.1R9 allows remote authenticated admins to conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML request.
network
low complexity
pulsesecure ivanti CWE-611
7.2
2020-09-30 CVE-2020-8256 XXE vulnerability in multiple products
A vulnerability in the Pulse Connect Secure < 9.1R8.2 admin web interface could allow an authenticated attacker to gain arbitrary file reading access through Pulse Collaboration via XML External Entity (XXE) vulnerability.
network
low complexity
pulsesecure ivanti CWE-611
4.9
2020-09-30 CVE-2020-8238 Cross-site Scripting vulnerability in multiple products
A vulnerability in the authenticated user web interface of Pulse Connect Secure and Pulse Policy Secure < 9.1R8.2 could allow attackers to conduct Cross-Site Scripting (XSS).
network
low complexity
pulsesecure ivanti CWE-79
6.1
2020-07-30 CVE-2020-8222 Path Traversal vulnerability in multiple products
A path traversal vulnerability exists in Pulse Connect Secure <9.1R8 that allowed an authenticated attacker via the administrator web interface to perform an arbitrary file reading vulnerability through Meeting.
network
low complexity
pulsesecure ivanti CWE-22
6.8
2020-07-30 CVE-2020-8221 Path Traversal vulnerability in multiple products
A path traversal vulnerability exists in Pulse Connect Secure <9.1R8 which allows an authenticated attacker to read arbitrary files via the administrator web interface.
network
low complexity
pulsesecure ivanti CWE-22
4.9