Patch & vulnerability status
Pulse Secure 22.8.3.35577
Latest tracked version 22.8.3.35577. Release status, tracked CVEs, and automated cross-platform patching for Pulse Secure.
| Platform | Latest version | CVEs tracked | Last checked |
|---|---|---|---|
| Windows | 22.8.3.35577 | 7 | 2024-05-23 |
Known vulnerabilities (CVEs) in Pulse Secure
Lavawall tracks 7 published CVEs affecting Pulse Secure, and deploys the versions that fix them automatically across your fleet.
| CVE | Published | Severity | Details | Vector |
|---|---|---|---|---|
| CVE-2020-8217 | 2020-07-30 13:15:12 | MEDIUM (5) | A cross site scripting (XSS) vulnerability in Pulse Connect Secure <9.1R8 allowed attackers to exploit in the URL used for Citrix ICA. | NETWORK |
| CVE-2020-8206 | 2020-07-30 13:15:12 | HIGH (8) | An improper authentication vulnerability exists in Pulse Connect Secure <9.1RB that allows an attacker with a users primary credentials to bypass the Google TOTP. | NETWORK |
| CVE-2020-11582 | 2020-04-06 21:15:14 | HIGH (9) | An issue was discovered in Pulse Secure Pulse Connect Secure (PCS) through 2020-04-06. The applet in tncc.jar, executed on macOS, Linux, and Solaris clients when a Host Checker policy is enforced, launches a TCP server that accepts local connections on a random port. This can be reached by local HTTP clients, because up to 25 invalid lines are ignored, and because DNS rebinding can occur. (This server accepts, for example, a setcookie command that might be relevant to CVE-2020-11581 exploitation.) | ADJACENT_NETWORK |
| CVE-2020-11581 | 2020-04-06 21:15:14 | HIGH (8) | An issue was discovered in Pulse Secure Pulse Connect Secure (PCS) through 2020-04-06. The applet in tncc.jar, executed on macOS, Linux, and Solaris clients when a Host Checker policy is enforced, allows a man-in-the-middle attacker to perform OS command injection attacks (against a client) via shell metacharacters to the doCustomRemediateInstructions method, because Runtime.getRuntime().exec() is used. | NETWORK |
| CVE-2020-11580 | 2020-04-06 21:15:14 | CRITICAL (9) | An issue was discovered in Pulse Secure Pulse Connect Secure (PCS) through 2020-04-06. The applet in tncc.jar, executed on macOS, Linux, and Solaris clients when a Host Checker policy is enforced, accepts an arbitrary SSL certificate. | NETWORK |
| CVE-2016-0800 | 2016-03-01 20:59:00 | MEDIUM (4) | The SSLv2 protocol, as used in OpenSSL before 1.0.1s and 1.0.2 before 1.0.2g and other products, requires a server to send a ServerVerify message before establishing that a client possesses certain plaintext RSA data, which makes it easier for remote attackers to decrypt TLS ciphertext data by leveraging a Bleichenbacher RSA padding oracle, aka a "DROWN" attack. | NETWORK |
| CVE-2016-0799 | 2016-03-03 20:59:04 | HIGH (10) | The fmtstr function in crypto/bio/b_print.c in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g improperly calculates string lengths, which allows remote attackers to cause a denial of service (overflow and out-of-bounds read) or possibly have unspecified other impact via a long string, as demonstrated by a large amount of ASN.1 data, a different vulnerability than CVE-2016-2842. | NETWORK |
Why keeping Pulse Secure patched matters
Unpatched third-party applications are one of the most common ways attackers get in: 57% of breached MSP clients and 32% of ransomware cases trace back to a missing patch. Every Pulse Secure release that fixes a security bug is public, so attackers see it too, and an out-of-date install becomes a documented way in. Tracking the installed version on every machine and closing the gap quickly is what turns a disclosed CVE into a non-event.
How Lavawall® patches Pulse Secure
Lavawall® watches Pulse Secure releases and CVEs continuously, ranks each update by risk, and deploys it across your whole fleet, Windows, macOS, and Linux, from a single agent, independently of your RMM. You get one place to see which machines are behind on Pulse Secure, one policy to bring them current, and timestamped evidence for audits.
Frequently asked questions
Lavawall tracks Pulse Secure at version 22.8.3.35577 (last checked 2024-05-23). New releases are monitored continuously and can be deployed automatically across your fleet.
Lavawall tracks 7 CVEs for Pulse Secure and remediates them automatically as part of patching.
Deploy the Lavawall® agent and Pulse Secure updates are applied automatically across Windows, macOS, and Linux, risk-ranked and reported, independently of your RMM.
Lavawall® monitors releases and CVEs for Pulse Secure through public information and proprietary statistical analysis, and can patch it automatically across your fleet.