QID 38899
Date Published: 2023-07-06
QID 38899: Ivanti Pulse Connect Secure Client Side Desync Attack Vulnerability (SA45476)
Pulse Connect Secure provides secure, authenticated access for remote and mobile users from any web-enabled device to corporate resources anytime, anywhere. Pulse Connect Secure is the most widely deployed SSL VPN for organizations of any size, across every major industry.
Affected Versions:
Pulse Connect Secure (PCS) 9.1R15 and below.
QID Detection Logic:(Authenticated)
This QID checks for vulnerable version of Pulse Connect Secure.
Successful exploitation of this vulnerability may be susceptible to client-side http request smuggling, When the application receives a POST request, it ignores the request's Content-Length header and leaves the POST body on the TCP/TLS socket. This body ends up prefixing the next HTTP request sent down that connection, this means when someone loads website attacker may be able to make browser issue a POST to the application, enabling XSS.
CVEs related to QID 38899
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| SA45476 |
|