CVE-2017-11193
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Pulse Connect Secure 8.3R1 has CSRF in diag.cgi. In the panel, the diag.cgi file is responsible for running commands such as ping, ping6, traceroute, traceroute6, nslookup, arp, and Portprobe. These functions do not have any protections against CSRF. That can allow an attacker to run these commands against any IP if they can get an admin to visit their malicious CSRF page.
Pulse Connect Secure versión 8.3R1, presenta un problema de tipo CSRF en el archivo diag.cgi. En el panel, el archivo diag.cgi es responsable de ejecutar comandos como ping, ping6, traceroute, traceroute6, nslookup, arp y Portprobe. Estas funciones no tienen ninguna protección contra CSRF. Eso puede permitir que un atacante ejecute estos comandos contra cualquier IP si pueden lograr que un administrador visite su página CSRF maliciosa.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-07-12 CVE Reserved
- 2017-07-12 CVE Published
- 2023-03-07 EPSS Updated
- 2024-08-05 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-352: Cross-Site Request Forgery (CSRF)
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/99621 | Vdb Entry | |
http://www.sxcurity.pro/Multiple%20XSS%20and%20CSRF%20in%20Pulse%20Connect%20Secure%20v8.3R1.pdf | Third Party Advisory | |
https://twitter.com/sxcurity/status/884556905145937921 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Pulsesecure Search vendor "Pulsesecure" | Pulse Connect Secure Search vendor "Pulsesecure" for product "Pulse Connect Secure" | 8.3r1.0 Search vendor "Pulsesecure" for product "Pulse Connect Secure" and version "8.3r1.0" | - |
Affected
|