CVE-2016-4791
Published on: 05/26/2016 12:00:00 AM UTC
Last Modified on: 03/23/2021 11:26:58 PM UTC
Certain versions of Pulse Connect Secure from Pulsesecure contain the following vulnerability:
The administrative user interface in Pulse Connect Secure (PCS) 8.2 before 8.2r1, 8.1 before 8.1r2, 8.0 before 8.0r9, and 7.4 before 7.4r13.4 allows remote administrators to enumerate files, read arbitrary files, and conduct server side request forgery (SSRF) attacks via unspecified vectors.
- CVE-2016-4791 has been assigned by [email protected] to track the vulnerability - currently rated as HIGH severity.
CVSS3 Score: 8.6 - HIGH
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | NONE | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
CHANGED | NONE | HIGH | NONE |
CVSS2 Score: 6.4 - MEDIUM
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
NETWORK | LOW | NONE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
PARTIAL | PARTIAL | NONE |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Public KB - SA40210 - [Pulse Secure] Information disclosure possible on admin UI (CVE-2016-4791) | Vendor Advisory kb.pulsesecure.net text/html | CONFIRM kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA40210 |
Pulse Connect Secure Bugs Let Remote Users Deny Service, Obtain Potentially Sensitive Information, and Conduct Cross-Site Scripting Attacks - SecurityTracker | www.securitytracker.com text/html | SECTRACK 1035932 |
There are currently no QIDs associated with this CVE
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Pulsesecure | Pulse Connect Secure | 7.4 | All | All | All |
Application | Pulsesecure | Pulse Connect Secure | 8.0 | All | All | All |
Application | Pulsesecure | Pulse Connect Secure | 8.1 | All | All | All |
Application | Pulsesecure | Pulse Connect Secure | 8.1r1.0 | All | All | All |
Application | Pulsesecure | Pulse Connect Secure | 8.2 | All | All | All |
Application | Pulsesecure | Pulse Connect Secure | 7.4 | All | All | All |
Application | Pulsesecure | Pulse Connect Secure | 8.0 | All | All | All |
Application | Pulsesecure | Pulse Connect Secure | 8.1 | All | All | All |
Application | Pulsesecure | Pulse Connect Secure | 8.1r1.0 | All | All | All |
Application | Pulsesecure | Pulse Connect Secure | 8.2 | All | All | All |
- cpe:2.3:a:pulsesecure:pulse_connect_secure:7.4:*:*:*:*:*:*:*:
- cpe:2.3:a:pulsesecure:pulse_connect_secure:8.0:*:*:*:*:*:*:*:
- cpe:2.3:a:pulsesecure:pulse_connect_secure:8.1:*:*:*:*:*:*:*:
- cpe:2.3:a:pulsesecure:pulse_connect_secure:8.1r1.0:*:*:*:*:*:*:*:
- cpe:2.3:a:pulsesecure:pulse_connect_secure:8.2:*:*:*:*:*:*:*:
- cpe:2.3:a:pulsesecure:pulse_connect_secure:7.4:*:*:*:*:*:*:*:
- cpe:2.3:a:pulsesecure:pulse_connect_secure:8.0:*:*:*:*:*:*:*:
- cpe:2.3:a:pulsesecure:pulse_connect_secure:8.1:*:*:*:*:*:*:*:
- cpe:2.3:a:pulsesecure:pulse_connect_secure:8.1r1.0:*:*:*:*:*:*:*:
- cpe:2.3:a:pulsesecure:pulse_connect_secure:8.2:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE