PT-2017-12023 · Pulse · Pulse Connect Secure+1
CVE-2017-11455
·
Publicado
2017-08-29
·
Atualizado
2024-02-27
CVSS v3.1
8.8
Alta
| Vetor | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Pulse Connect Secure versions 8.2R1 through 8.2R5
Pulse Connect Secure versions 8.1R1 through 8.1R10
Pulse Policy Secure versions 5.3R1 through 5.3R5
Pulse Policy Secure versions 5.2R1 through 5.2R8
Pulse Policy Secure versions 5.1R1 through 5.1R10
Description
The issue allows remote attackers to hijack the authentication of administrators for requests to start tcpdump, related to the lack of anti-CSRF tokens in the diag.cgi component.
Recommendations
For Pulse Connect Secure versions 8.2R1 through 8.2R5, consider disabling access to the diag.cgi component until a patch is available.
For Pulse Connect Secure versions 8.1R1 through 8.1R10, consider disabling access to the diag.cgi component until a patch is available.
For Pulse Policy Secure versions 5.3R1 through 5.3R5, consider disabling access to the diag.cgi component until a patch is available.
For Pulse Policy Secure versions 5.2R1 through 5.2R8, consider disabling access to the diag.cgi component until a patch is available.
For Pulse Policy Secure versions 5.1R1 through 5.1R10, consider disabling access to the diag.cgi component until a patch is available.
Correção
CSRF
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Pulse Connect Secure
Pulse Policy Secure