In Ivanti Pulse Secure Pulse Connect Secure (PCS) before 9.1R12, the administrator password is stored in the HTML source code of the Maintenance > Push Configuration > Targets > Target Name targets.cgi screen. A read-only administrative user can escalate to a read-write administrative role.
The product contains hard-coded credentials, such as a password or cryptographic key.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Connect_secure | Ivanti | 9.1 (including) | 9.1 (including) |
Connect_secure | Ivanti | 9.1-r1 (including) | 9.1-r1 (including) |
Connect_secure | Ivanti | 9.1-r10.0 (including) | 9.1-r10.0 (including) |
Connect_secure | Ivanti | 9.1-r11.0 (including) | 9.1-r11.0 (including) |
Connect_secure | Ivanti | 9.1-r11.3 (including) | 9.1-r11.3 (including) |
Connect_secure | Ivanti | 9.1-r11.4 (including) | 9.1-r11.4 (including) |
Connect_secure | Ivanti | 9.1-r2 (including) | 9.1-r2 (including) |
Connect_secure | Ivanti | 9.1-r3 (including) | 9.1-r3 (including) |
Connect_secure | Ivanti | 9.1-r4 (including) | 9.1-r4 (including) |
Connect_secure | Ivanti | 9.1-r4.1 (including) | 9.1-r4.1 (including) |
Connect_secure | Ivanti | 9.1-r4.2 (including) | 9.1-r4.2 (including) |
Connect_secure | Ivanti | 9.1-r4.3 (including) | 9.1-r4.3 (including) |
Connect_secure | Ivanti | 9.1-r5 (including) | 9.1-r5 (including) |
Connect_secure | Ivanti | 9.1-r6 (including) | 9.1-r6 (including) |
Connect_secure | Ivanti | 9.1-r7 (including) | 9.1-r7 (including) |
Connect_secure | Ivanti | 9.1-r8 (including) | 9.1-r8 (including) |
Connect_secure | Ivanti | 9.1-r8.1 (including) | 9.1-r8.1 (including) |
Connect_secure | Ivanti | 9.1-r8.2 (including) | 9.1-r8.2 (including) |
Connect_secure | Ivanti | 9.1-r9 (including) | 9.1-r9 (including) |
Connect_secure | Ivanti | 9.1-r9.1 (including) | 9.1-r9.1 (including) |
Pulse_connect_secure | Pulsesecure | * | 9.1 (excluding) |
There are two main variations: