mirror of
https://github.com/0xMarcio/cve.git
synced 2025-05-29 01:31:01 +00:00
19 lines
880 B
Markdown
19 lines
880 B
Markdown
![]() |
### [CVE-2019-11540](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-11540)
|
||
|

|
||
|

|
||
|

|
||
|
|
||
|
### Description
|
||
|
|
||
|
In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4 and 8.3RX before 8.3R7.1 and Pulse Policy Secure version 9.0RX before 9.0R3.2 and 5.4RX before 5.4R7.1, an unauthenticated, remote attacker can conduct a session hijacking attack.
|
||
|
|
||
|
### POC
|
||
|
|
||
|
#### Reference
|
||
|
- https://devco.re/blog/2019/09/02/attacking-ssl-vpn-part-3-the-golden-Pulse-Secure-ssl-vpn-rce-chain-with-Twitter-as-case-study/
|
||
|
|
||
|
#### Github
|
||
|
- https://github.com/gquere/PulseSecure_session_hijacking
|
||
|
- https://github.com/jaychouzzk/Pulse-Secure-SSL-VPN-CVE-2019
|
||
|
|