CVE-2019-11213
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
In Pulse Secure Pulse Desktop Client and Network Connect, an attacker could access session tokens to replay and spoof sessions, and as a result, gain unauthorized access as an end user, a related issue to CVE-2019-1573. (The endpoint would need to be already compromised for exploitation to succeed.) This affects Pulse Desktop Client 5.x before Secure Desktop 5.3R7 and Pulse Desktop Client 9.x before Secure Desktop 9.0R3. It also affects (for Network Connect customers) Pulse Connect Secure 8.1 before 8.1R14, 8.3 before 8.3R7, and 9.0 before 9.0R3.
En Pulse Secure Pulse Desktop Client y Network Connect, un atacante podría acceder a los tokens de sesión para responder y suplantar sesiones, y , como resultado, obtener acceso no autorizado como usuario final, un problema relacionado con el identificador CVE-2019-1573. (El endpoint tendría que estar ya comprometido para que la explotación tenga éxito.) Esto afecta a Pulse Desktop Client 5.x anterior a Secure Desktop 5.3R7 y a Pulse Desktop Client 9.x anterior a Secure Desktop 9.0R3. También afecta (para clientes Network Connect) a Pulse Connect Secure 8.1 anterior a 8.1R14, 8.3 anterior a 8.3R7, y 9.0 anterior a 9.0R3.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-04-12 CVE Reserved
- 2019-04-12 CVE Published
- 2024-04-05 EPSS Updated
- 2024-08-04 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-384: Session Fixation
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://www.kb.cert.org/vuls/id/192371 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44114 | 2024-02-27 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Ivanti Search vendor "Ivanti" | Connect Secure Search vendor "Ivanti" for product "Connect Secure" | >= 9.0r1 < 9.0r3 Search vendor "Ivanti" for product "Connect Secure" and version " >= 9.0r1 < 9.0r3" | - |
Affected
| ||||||
Pulsesecure Search vendor "Pulsesecure" | Pulse Connect Secure Search vendor "Pulsesecure" for product "Pulse Connect Secure" | >= 8.1r1.0 <= 8.1r14.0 Search vendor "Pulsesecure" for product "Pulse Connect Secure" and version " >= 8.1r1.0 <= 8.1r14.0" | - |
Affected
| ||||||
Pulsesecure Search vendor "Pulsesecure" | Pulse Connect Secure Search vendor "Pulsesecure" for product "Pulse Connect Secure" | >= 8.3r1 < 8.3r7 Search vendor "Pulsesecure" for product "Pulse Connect Secure" and version " >= 8.3r1 < 8.3r7" | - |
Affected
| ||||||
Pulsesecure Search vendor "Pulsesecure" | Pulse Secure Desktop Client Search vendor "Pulsesecure" for product "Pulse Secure Desktop Client" | >= 5.0r1.0 < 5.3r7 Search vendor "Pulsesecure" for product "Pulse Secure Desktop Client" and version " >= 5.0r1.0 < 5.3r7" | - |
Affected
| ||||||
Pulsesecure Search vendor "Pulsesecure" | Pulse Secure Desktop Client Search vendor "Pulsesecure" for product "Pulse Secure Desktop Client" | >= 9.0r1 < 9.0r3 Search vendor "Pulsesecure" for product "Pulse Secure Desktop Client" and version " >= 9.0r1 < 9.0r3" | - |
Affected
|