Pulse Connect Secure SSL VPN arbitrary file read vulnerability

Published on 01 Oct 2021
Vulnerability

In Pulse Connect Secure(PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthenticated attacker with network access via HTTPS can send a specially crafted URL to perform an arbitrary file reading vulnerability.

Impact

This arbitrary file read vulnerability can lead to the leakage of sensitive information, allowing unauthorized remote attackers to read the private key and user password; furthermore, it can even trigger a remote command injection attack(CVE-2019-11539).

Mitigation / Precaution

Our recommendation is to upgrade the Pulse Connect Secure to the latest version as soon as possible to patch the vulnerabilities.

Nash N Sulthan
Written by
Cyber Security Lead Engineer

Nash is a seasoned Security Engineer who brings a multifaceted approach to safeguarding digital environments. Not only does he excel in implementing robust security measures, but he's also deeply involved in the research and development process, constantly innovating to stay ahead of cyber threats. Nash's commitment to security extends beyond the conventional, making him a valuable contributor to the evolving landscape of digital defense.

Experience the Beagle Security platform
Unlock one full penetration test and all Advanced plan features free for 14 days
4.8 on G2 • ISO 27001 certified
See How Beagle Security Works
No credit card • No setup required
Launch interactive demo