In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1RX before 8.1R15.1, an NFS problem could allow an authenticated attacker to access the contents of arbitrary files on the affected device.
References
Link | Resource |
---|---|
http://www.securityfocus.com/bid/108073 | Third Party Advisory VDB Entry |
https://devco.re/blog/2019/09/02/attacking-ssl-vpn-part-3-the-golden-Pulse-Secure-ssl-vpn-rce-chain-with-Twitter-as-case-study/ | Exploit Third Party Advisory |
https://i.blackhat.com/USA-19/Wednesday/us-19-Tsai-Infiltrating-Corporate-Intranet-Like-NSA.pdf | Exploit Third Party Advisory |
https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44101 | Vendor Advisory |
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2019-0010 | Third Party Advisory |
https://www.kb.cert.org/vuls/id/927237 | Third Party Advisory US Government Resource |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2019-04-26 02:29
Updated : 2024-02-27 21:04
NVD link : CVE-2019-11538
Mitre link : CVE-2019-11538
CVE.ORG link : CVE-2019-11538
JSON object : View
Products Affected
ivanti
- connect_secure
CWE
CWE-59
Improper Link Resolution Before File Access ('Link Following')