Pulse Secure Known Exploited Vulnerabilities

Evidence-backed KEV intelligence for Pulse Secure products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.

Total KEVs

9

In CISA KEV

9

Beyond CISA KEV

0

Sensor Observed

0

Virtual Patch Available

0

Pulse Secure KEVs Added by Year

Loading...

9 Pulse Secure KEVs added all time (primary attestation date).

Attested CVEs

CVE Confidence CISA KEV Added
CVE-2019-11539

In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1RX before 8.1R15.1 and Pulse...

Confirmed In CISA 03 Nov 2021
CVE-2019-11510

In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthenticated remote attacker can...

Confirmed In CISA 03 Nov 2021
CVE-2021-22899

A command injection vulnerability exists in Pulse Connect Secure before 9.1R11.4 allows a remote authenticated attacker to perform remote code...

Confirmed In CISA 03 Nov 2021
CVE-2020-8260

A vulnerability in the Pulse Connect Secure < 9.1R9 admin web interface could allow an authenticated attacker to perform an arbitrary code...

Confirmed In CISA 03 Nov 2021
CVE-2021-22894

A buffer overflow vulnerability exists in Pulse Connect Secure before 9.1R11.4 allows a remote authenticated attacker to execute arbitrary code as...

Confirmed In CISA 03 Nov 2021
CVE-2021-22900

A vulnerability allowed multiple unrestricted uploads in Pulse Connect Secure before 9.1R11.4 that could lead to an authenticated administrator to...

Confirmed In CISA 03 Nov 2021
CVE-2020-8243

A vulnerability in the Pulse Connect Secure < 9.1R8.2 admin web interface could allow an authenticated attacker to upload custom template to...

Confirmed In CISA 03 Nov 2021
CVE-2021-22893

Pulse Connect Secure 9.0R3/9.1R1 and higher is vulnerable to an authentication bypass vulnerability exposed by the Windows File Share Browser and...

Confirmed In CISA 03 Nov 2021
CVE-2020-8218

A code injection vulnerability exists in Pulse Connect Secure <9.1R8 that allows an attacker to crafted a URI to perform an arbitrary code...

Confirmed In CISA 07 Mar 2022

Common Vulnerability Classes (CWE)

  • CWE-94 — Improper Control of Generation of Code ('Code Injection') 4
  • CWE-22 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 1
  • CWE-287 — Improper Authentication 1
  • CWE-434 — Unrestricted Upload of File with Dangerous Type 1
  • CWE-77 — Improper Neutralization of Special Elements used in a Command ('Command Injection') 1
  • CWE-78 — Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') 1

Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology