QID 38846

Date Published: 2021-08-03

QID 38846: Pulse Connect Secure and Pulse Policy Secure NULL Pointer Dereference (SA44676)

Pulse Connect Secure provides secure, authenticated access for remote and mobile users from any web-enabled device to corporate resources anytime, anywhere. Pulse Connect Secure is the most widely deployed SSL VPN for organizations of any size, across every major industry.

Affected Versions:
Pulse Connect Secure (PCS) prior to 9.1R12
Pulse Policy Secure (PPS) prior to 9.1R12

QID Detection Logic:(Authenticated)
This QID checks for vulnerable version of Pulse Secure Desktop, Pulse Connect Secure and Pulse Policy Secure.

An attacker can leverage this vulnerability to NULL pointer dereference and a crash may occur leading to a possible denial of service attack.

  • CVSS V3 rated as Medium - 5.9 severity.
  • CVSS V2 rated as Medium - 4.3 severity.
  • Solution
    Patches are not available. Please visit SA44676 please check here for more information.

    CVEs related to QID 38846

    Software Advisories
    Advisory ID Software Component Link