Multiple Vulnerabilities in Pulse Secure VPN
by CIRT Team
Description:
The CERT Coordination Center (CERT/CC) has released information on multiple vulnerabilities affecting Pulse Secure Virtual Private Network (VPN). An attacker could exploit these vulnerabilities to take control of an affected system. These vulnerabilities have been targeted by advanced persistent threat (APT) actors.
Impact: A remote attacker could exploit this vulnerability to take control of an affected system.
Mitigation: Updates are available. Please see the references or vendor advisory for more information.
Reference URL’s:
- https://www.kb.cert.org/vuls/id/927237/
- https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44101
- https://media.defense.gov/2019/Oct/07/2002191601/-1/-1/0/CSA-MITIGATING-RECENT-VPN-VULNERABILITIES.PDF
- https://www.us-cert.gov/ncas/current-activity/2019/07/26/vulnerabilities-multiple-vpn-applications
Recommended Posts
Active Exploitation of Critical F5 BIG – IP Vulnerability (CVE–2023-46747) Uncovered in Bangladesh
06 Nov 2024 - Security Advisories & Alerts