VulnerabilityModified
CVE-2020-15408
An authenticated attacker can access the admin page console via the end-user web interface because of a rewrite.
MEDIUM 4.6EPSS 0.77%
Does this matter?
Lower severity and a low EPSS score (0.77%). Track it; it rarely justifies an emergency change on its own.
Description
An issue was discovered in Pulse Secure Pulse Connect Secure before 9.1R8. An authenticated attacker can access the admin page console via the end-user web interface because of a rewrite.
- CVSS 3.1
- 4.6 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
- EPSS
- 0.77% probability · 54th percentile
- CISA KEV
- Not listed
- Affected
- pulsesecure/pulse connect secure · pulsesecure/pulse secure desktop client
- Source
- cve@mitre.org
References
- https://kb.pulsesecure.net/?atype=saVendor Advisory
- https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44516Vendor Advisory
- https://kb.pulsesecure.net/?atype=saVendor Advisory
- https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44516Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.