5.8

CVE-2020-15408

An issue was discovered in Pulse Secure Pulse Connect Secure before 9.1R8. An authenticated attacker can access the admin page console via the end-user web interface because of a rewrite.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Pulsesecure ≫ Pulse Connect Secure Version <= 9.1
Pulsesecure ≫ Pulse Secure Desktop Client Version 9.1 Update r1.0
Pulsesecure ≫ Pulse Secure Desktop Client Version 9.1 Update r2.0
Pulsesecure ≫ Pulse Secure Desktop Client Version 9.1 Update r3.0
Pulsesecure ≫ Pulse Secure Desktop Client Version 9.1 Update r3.1
Pulsesecure ≫ Pulse Secure Desktop Client Version 9.1 Update r4.0
Pulsesecure ≫ Pulse Secure Desktop Client Version 9.1 Update r4.1
Pulsesecure ≫ Pulse Secure Desktop Client Version 9.1 Update r4.2
Pulsesecure ≫ Pulse Secure Desktop Client Version 9.1 Update r5.0
Pulsesecure ≫ Pulse Secure Desktop Client Version 9.1 Update r6.0
Pulsesecure ≫ Pulse Secure Desktop Client Version 9.1 Update r7.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.77% 0.508
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4.6 2.1 2.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
NIST 5.8 8.6 4.9
AV:N/AC:M/Au:N/C:P/I:P/A:N
MITRE 3.7 1.2 2.5
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44516
Vendor Advisory
https://kb.pulsesecure.net/?atype=sa
Vendor Advisory