Multiple Vulnerabilities in Pulse Secure VPN
Description:
The CERT Coordination Center (CERT/CC) has released information on multiple vulnerabilities affecting Pulse Secure Virtual Private Network (VPN). An attacker could exploit these vulnerabilities to take control of an affected system. These vulnerabilities have been targeted by advanced persistent threat (APT) actors.
Impact: A remote attacker could exploit this vulnerability to take control of an affected system.
Mitigation: Updates are available. Please see the references or vendor advisory for more information.
Reference URL’s:
- https://www.kb.cert.org/vuls/id/927237/
- https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44101
- https://media.defense.gov/2019/Oct/07/2002191601/-1/-1/0/CSA-MITIGATING-RECENT-VPN-VULNERABILITIES.PDF
- https://www.us-cert.gov/ncas/current-activity/2019/07/26/vulnerabilities-multiple-vpn-applications
Recommended Posts
Multiple Vulnerabilities in SolarWinds Orion and ServU-FTP Could Allow for Remote Code Execution
01 Mar 2021 - Security Advisories & Alerts