CVE Vulnerabilities

CVE-2020-15408

Published: Jul 28, 2020 | Modified: Nov 21, 2024
CVSS 3.x
4.6
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
CVSS 2.x
5.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

An issue was discovered in Pulse Secure Pulse Connect Secure before 9.1R8. An authenticated attacker can access the admin page console via the end-user web interface because of a rewrite.

Affected Software

NameVendorStart VersionEnd Version
Pulse_connect_securePulsesecure*9.1 (including)
Pulse_secure_desktop_clientPulsesecure9.1-r1.0 (including)9.1-r1.0 (including)
Pulse_secure_desktop_clientPulsesecure9.1-r2.0 (including)9.1-r2.0 (including)
Pulse_secure_desktop_clientPulsesecure9.1-r3.0 (including)9.1-r3.0 (including)
Pulse_secure_desktop_clientPulsesecure9.1-r3.1 (including)9.1-r3.1 (including)
Pulse_secure_desktop_clientPulsesecure9.1-r4.0 (including)9.1-r4.0 (including)
Pulse_secure_desktop_clientPulsesecure9.1-r4.1 (including)9.1-r4.1 (including)
Pulse_secure_desktop_clientPulsesecure9.1-r4.2 (including)9.1-r4.2 (including)
Pulse_secure_desktop_clientPulsesecure9.1-r5.0 (including)9.1-r5.0 (including)
Pulse_secure_desktop_clientPulsesecure9.1-r6.0 (including)9.1-r6.0 (including)
Pulse_secure_desktop_clientPulsesecure9.1-r7.0 (including)9.1-r7.0 (including)

References