VulnerabilityModified
CVE-2019-11507
In Pulse Secure Pulse Connect Secure (PCS) 8.3.x before 8.3R7.1 and 9.0.x before 9.0R3, an XSS issue has been found on the Application Launcher page.
MEDIUM 6.1EPSS 4.06%
Does this matter?
Lower severity and a low EPSS score (4.06%). Track it; it rarely justifies an emergency change on its own.
Description
In Pulse Secure Pulse Connect Secure (PCS) 8.3.x before 8.3R7.1 and 9.0.x before 9.0R3, an XSS issue has been found on the Application Launcher page.
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 4.06% probability · 90th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- ivanti/connect secure
- Source
- cve@mitre.org
References
- http://www.securityfocus.com/bid/108073Broken Link, Third Party Advisory, VDB Entry
- https://devco.re/blog/2019/09/02/attacking-ssl-vpn-part-3-the-golden-Pulse-Secure-ssl-vpn-rce-chain-with-Twitter-as-case-study/Exploit, Third Party Advisory
- https://i.blackhat.com/USA-19/Wednesday/us-19-Tsai-Infiltrating-Corporate-Intranet-Like-NSA.pdfExploit, Third Party Advisory
- https://kb.pulsesecure.net/?atype=saThird Party Advisory, Vendor Advisory
- https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44101/Patch, Vendor Advisory
- https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44516Third Party Advisory
- https://www.kb.cert.org/vuls/id/927237Third Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/108073Broken Link, Third Party Advisory, VDB Entry
- https://devco.re/blog/2019/09/02/attacking-ssl-vpn-part-3-the-golden-Pulse-Secure-ssl-vpn-rce-chain-with-Twitter-as-case-study/Exploit, Third Party Advisory
- https://i.blackhat.com/USA-19/Wednesday/us-19-Tsai-Infiltrating-Corporate-Intranet-Like-NSA.pdfExploit, Third Party Advisory
- https://kb.pulsesecure.net/?atype=saThird Party Advisory, Vendor Advisory
- https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44101/Patch, Vendor Advisory
- https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44516Third Party Advisory
- https://www.kb.cert.org/vuls/id/927237Third Party Advisory, US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.