vendor:
Pulse Secure SSL VPN
by:
0xDezzy (Justin Wagner), Alyssa Herrera
10.0
CVSS
CRITICAL
File Disclosure
200
CWE
Product Name: Pulse Secure SSL VPN
Affected Version From: 8.1R15.1
Affected Version To: 9.0R3.4
Patch Exists: YES
Related CWE: CVE-2019-11510
CPE: a:pulsesecure:pulse_secure_ssl_vpn
Other Scripts:
N/A
Platforms Tested: Linux
2019
File disclosure in Pulse Secure SSL VPN (metasploit)
Pulse Secure SSL VPN file disclosure via specially crafted HTTP resource requests. This exploit reads /etc/passwd as a proof of concept. This vulnerability affect ( 8.1R15.1, 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4
Mitigation:
Upgrade to the latest version of Pulse Secure SSL VPN