QID 38839

Date Published: 2021-05-25

QID 38839: Pulse Connect Secure and Pulse Policy Secure Multiple Vulnerabilities (SA44800)

Pulse Connect Secure provides secure, authenticated access for remote and mobile users from any web-enabled device to corporate resources anytime, anywhere. Pulse Connect Secure is the most widely deployed SSL VPN for organizations of any size, across every major industry.

CVE-2021-22908 - Buffer Overflow in Windows File Resource Profiles in 9.X allows a remote authenticated user with privileges to browse SMB shares to execute arbitrary code as the root user. As of version 9.1R3, this permission is not enabled by default.

Affected Versions:
Pulse Connect Secure 9.0RX and Pulse Connect Secure 9.1RX

QID Detection logic:(Authenticated)
It uses snmpwalk request and oid to get the vulnerable version of Pulse Connect and Policy Secure at scan result.

Successful exploitation of this vulnerability affects confidentiality, integrity and availability.

  • CVSS V3 rated as Critical - 8.5 severity.
  • CVSS V2 rated as High - 7.6 severity.
  • Solution
    The Vendor has released fixes in Pulse Connect Secure 9.1R11.5. Please refer to SA44800 to re-mediate these vulnerabilities.

    Workaround:
    CVE-2021-22908 can be mitigated by importing the Workaround-2105.xml file in the workaround section

    CVEs related to QID 38839

    Software Advisories
    Advisory ID Software Component Link
    SA44800 URL Logo kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44800/?kA23Z000000boUgSAI