Pulse Secure Update
2934Warning Date
Severity Level
Warning Number
Target Sector
24 June, 2020
● Critical
2020-1389
All
Description:
Pulse Secure has released security update to address multiple vulnerabilities in the following products:
- Pulse Connect Secure
- 8.3Rx before 8.3R6
- 8.2Rx before 8.2R12
- 8.1Rx before 8.1R14
- 8.3.x before 8.2R7
- 9.0Rx before 9.0R4
- 9.0.x before 9.0R4
- Pulse Policy Secure
- 5.1Rx before 5.1R14
- 5.2Rx before 5.2R11
- 5.4Rx before 5.4R6
- 5.4.x before 5.4R7
- 9.0Rx before 9.0R4
- 9.0.x before 9.0R4
- Pulse Secure Desktop (For Windows):
- 9.0Rx before 9.0R
- 5.3Rx before 5.3R6
- 5.2Rx before 5.2R12
- 5.1Rx before 5.1R14
- 5.3Rx before 5.3R7
- Pulse Secure Desktop (For macOS):
- 9.0Rx before 9.0R2
- 5.3Rx before 5.3R6
- 5.2Rx before 5.2R12
- 5.1Rx before 5.1R14
Threats:
Attacker could exploit these vulnerabilities by doing the following:
- Cross-site scripting (XSS) attack.
- Buffer overflow.
- Execute arbitrary code.
Best practice and Recommendations:
The CERT team encourages users to update the affected products and to review Pulse Secure advisory: