← Back

CVE-2017-11455

nvd nist
Published: Aug 29, 2017Modified: May 13, 2026

JSON object

Loading...
8.8
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

diag.cgi in Pulse Connect Secure 8.2R1 through 8.2R5, 8.1R1 through 8.1R10 and Pulse Policy Secure 5.3R1 through 5.3R5, 5.2R1 through 5.2R8, and 5.1R1 through 5.1R10 allow remote attackers to hijack the authentication of administrators for requests to start tcpdump, related to the lack of anti-CSRF tokens.

Affected (47)

1 product
Connect Secure
2 products
Pulse Connect Secure
Pulse Policy Secure
Configuration A
10 vulnerable
Configuration B
37 vulnerable
Vulnerable SoftwareAffected Versions
Pulsesecure
Version 5.1r1.0
Version 5.1r1.1
Version 5.1r10
Version 5.1r2.0
Version 5.1r2.1
Version 5.1r3.0
Version 5.1r3.2
Version 5.1r4.0
Version 5.1r5.0
Version 5.1r6.0
Version 5.1r7.0
Version 5.1r7.1
Version 5.1r8.0
Version 5.1r9.1
Version 5.2r1.0
Version 5.2r2.0
Version 5.2r3.0
Version 5.2r3.2
Version 5.2r4.0
Version 5.2r5.0
Version 5.2r6.0
Version 5.2r7.0
Version 5.2r7.1
Version 5.2r8.0
Version 5.3r1.0
Version 5.3r1.1
Version 5.3r2.0
Version 5.3r3.0
Version 5.3r3.1
Version 5.3r4.0
Version 5.3r4.1
Version 5.3r5.0
Version 5.3r5.1
Version 5.3r5.2
Version 5.3r6.0
Version 5.3r7.0
Version 5.3r8.0

References (6)

Source: cve@mitre.org
Third Party AdvisoryVDB Entry
Source: cve@mitre.org
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.