QID 730304

QID 730304: Pulse Connect Secure Multiple Vulnerabilities (SA44858) (Unauthenticated Check)

Pulse Connect Secure provides secure, authenticated access for remote and mobile users from any web-enabled device to corporate resources anytime, anywhere. Pulse Connect Secure is the most widely deployed SSL VPN for organizations of any size, across every major industry.

Affected Versions:
Pulse Connect Secure (PCS) prior to 9.1R12
QID Detection Logic:(Unauthenticated)
This QID checks for vulnerable version of Pulse Connect Secure by grabbing the version from /dana-na/nc/nc_gina_ver.txt file.

This could allow an authenticated administrator to perform a file write via a maliciously crafted archive uploaded in the administrator web interface.

  • CVSS V3 rated as High - 7.2 severity.
  • CVSS V2 rated as High - 6.5 severity.
  • Solution
    The vendor has released fixes. Please visit SA44858 please check here for more information.

    Software Advisories
    Advisory ID Software Component Link
    SA44858 URL Logo kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44858