CVE-2019-11541 Information

Description

In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4 8.3RX before 8.3R7.1 and 8.2RX before 8.2R12.1 users using SAML authentication with the Reuse Existing NC (Pulse) Session option may see authentication leaks.

CVSS Vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Reference

http://www.securityfocus.com/bid/108073 https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44101 https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44101/ https://www.kb.cert.org/vuls/id/927237

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

HIGH

Availability Impact

NONE

Base Score

NONE

Base Severity

7.5

Share on: