Pulse Secure Warning
3097Warning Date
Severity Level
Warning Number
Target Sector
9 April, 2020
● High
2020-1120
All
Description:
Pulse Secure has released security warning to address multiple vulnerabilities in the following products
- Pulse Connect Secure
- Pulse Policy Secure
Threats:
Attacker could exploit these vulnerabilities by doing the following:
- Man in the middle attack
- Execute arbitrary code - remotely
Best practice and Recommendations:
- Safari 12 and above no longer supports NPAPI. if you are using older version, please upgrade your browsers to latest version.
- Google's Chrome version 45 and above have dropped support for NPAPI, and therefore Java Plugin do not work on these browsers anymore.
- Firefox no longer offers a version which supports NPAPI. Firefox version 52ESR is the last release to support the technology.
- If end users are using 52ESR, Please recommend to upgrade the browser to latest version or use Pulse Secure Linux Client.
- For more information:
https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44426/?kA23Z000000L6fASAS