5.8

CVE-2020-15408

An issue was discovered in Pulse Secure Pulse Connect Secure before 9.1R8. An authenticated attacker can access the admin page console via the end-user web interface because of a rewrite.

Data is provided by the National Vulnerability Database (NVD)
PulsesecurePulse Connect Secure Version <= 9.1
PulsesecurePulse Secure Desktop Client Version9.1 Updater1.0
PulsesecurePulse Secure Desktop Client Version9.1 Updater2.0
PulsesecurePulse Secure Desktop Client Version9.1 Updater3.0
PulsesecurePulse Secure Desktop Client Version9.1 Updater3.1
PulsesecurePulse Secure Desktop Client Version9.1 Updater4.0
PulsesecurePulse Secure Desktop Client Version9.1 Updater4.1
PulsesecurePulse Secure Desktop Client Version9.1 Updater4.2
PulsesecurePulse Secure Desktop Client Version9.1 Updater5.0
PulsesecurePulse Secure Desktop Client Version9.1 Updater6.0
PulsesecurePulse Secure Desktop Client Version9.1 Updater7.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.33% 0.526
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4.6 2.1 2.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
nvd@nist.gov 5.8 8.6 4.9
AV:N/AC:M/Au:N/C:P/I:P/A:N
cve@mitre.org 3.7 1.2 2.5
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N