5.8

CVE-2020-15408

An issue was discovered in Pulse Secure Pulse Connect Secure before 9.1R8. An authenticated attacker can access the admin page console via the end-user web interface because of a rewrite.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
PulsesecurePulse Connect Secure Version <= 9.1
PulsesecurePulse Secure Desktop Client Version9.1 Updater1.0
PulsesecurePulse Secure Desktop Client Version9.1 Updater2.0
PulsesecurePulse Secure Desktop Client Version9.1 Updater3.0
PulsesecurePulse Secure Desktop Client Version9.1 Updater3.1
PulsesecurePulse Secure Desktop Client Version9.1 Updater4.0
PulsesecurePulse Secure Desktop Client Version9.1 Updater4.1
PulsesecurePulse Secure Desktop Client Version9.1 Updater4.2
PulsesecurePulse Secure Desktop Client Version9.1 Updater5.0
PulsesecurePulse Secure Desktop Client Version9.1 Updater6.0
PulsesecurePulse Secure Desktop Client Version9.1 Updater7.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.33% 0.526
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.6 2.1 2.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
nvd@nist.gov 5.8 8.6 4.9
AV:N/AC:M/Au:N/C:P/I:P/A:N
cve@mitre.org 3.7 1.2 2.5
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N