Vulnerabilities > Pulsesecure > Medium

DATE CVE VULNERABILITY TITLE RISK
2022-09-30 CVE-2022-21826 HTTP Request Smuggling vulnerability in multiple products
Pulse Secure version 9.115 and below may be susceptible to client-side http request smuggling, When the application receives a POST request, it ignores the request's Content-Length header and leaves the POST body on the TCP/TLS socket.
network
low complexity
pulsesecure ivanti CWE-444
5.4
2021-08-16 CVE-2021-22933 Path Traversal vulnerability in multiple products
A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator to perform an arbitrary file delete via a maliciously crafted web request.
network
low complexity
pulsesecure ivanti CWE-22
6.5
2021-08-16 CVE-2021-22936 Cross-site Scripting vulnerability in multiple products
A vulnerability in Pulse Connect Secure before 9.1R12 could allow a threat actor to perform a cross-site script attack against an authenticated administrator via an unsanitized web parameter.
network
low complexity
pulsesecure ivanti CWE-79
6.1
2021-05-14 CVE-2021-31922 HTTP Request Smuggling vulnerability in Pulsesecure Virtual Traffic Manager
An HTTP Request Smuggling vulnerability in Pulse Secure Virtual Traffic Manager before 21.1 could allow an attacker to smuggle an HTTP request through an HTTP/2 Header.
network
low complexity
pulsesecure CWE-444
5.0
2020-10-28 CVE-2020-8262 Cross-site Scripting vulnerability in multiple products
A vulnerability in the Pulse Connect Secure / Pulse Policy Secure below 9.1R9 could allow attackers to conduct Cross-Site Scripting (XSS) and Open Redirection for authenticated user web interface.
network
low complexity
pulsesecure ivanti CWE-79
6.1
2020-10-28 CVE-2020-8261 Classic Buffer Overflow vulnerability in multiple products
A vulnerability in the Pulse Connect Secure / Pulse Policy Secure < 9.1R9 is vulnerable to arbitrary cookie injection.
network
low complexity
pulsesecure ivanti CWE-120
4.3
2020-10-28 CVE-2020-8260 Unrestricted Upload of File with Dangerous Type vulnerability in Pulsesecure Pulse Secure Desktop Client 9.1
A vulnerability in the Pulse Connect Secure < 9.1R9 admin web interface could allow an authenticated attacker to perform an arbitrary code execution using uncontrolled gzip extraction.
network
low complexity
pulsesecure CWE-434
6.5
2020-10-28 CVE-2020-8255 Unspecified vulnerability in Pulsesecure Pulse Secure Desktop Client 9.1
A vulnerability in the Pulse Connect Secure < 9.1R9 admin web interface could allow an authenticated attacker to perform an arbitrary file reading vulnerability is fixed using encrypted URL blacklisting that prevents these messages.
network
low complexity
pulsesecure
4.0
2020-10-28 CVE-2020-8254 Path Traversal vulnerability in Pulsesecure Pulse Secure Desktop Client
A vulnerability in the Pulse Secure Desktop Client < 9.1R9 has Remote Code Execution (RCE) if users can be convinced to connect to a malicious server.
6.8
2020-10-28 CVE-2020-8250 Unspecified vulnerability in Pulsesecure Pulse Secure Desktop Client 9.1
A vulnerability in the Pulse Secure Desktop Client (Linux) < 9.1R9 could allow local attackers to escalate privilege.
local
low complexity
pulsesecure
4.6