René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

315 lines
12 KiB
JSON

{
"id": "CVE-2021-22893",
"sourceIdentifier": "support@hackerone.com",
"published": "2021-04-23T17:15:08.127",
"lastModified": "2022-10-24T17:17:23.817",
"vulnStatus": "Analyzed",
"cisaExploitAdd": "2021-11-03",
"cisaActionDue": "2021-04-23",
"cisaRequiredAction": "Apply updates per vendor instructions.",
"cisaVulnerabilityName": "Pulse Connect Secure Remote Code Execution Vulnerability",
"descriptions": [
{
"lang": "en",
"value": "Pulse Connect Secure 9.0R3/9.1R1 and higher is vulnerable to an authentication bypass vulnerability exposed by the Windows File Share Browser and Pulse Secure Collaboration features of Pulse Connect Secure that can allow an unauthenticated user to perform remote arbitrary code execution on the Pulse Connect Secure gateway. This vulnerability has been exploited in the wild."
},
{
"lang": "es",
"value": "Pulse Connect Secure versiones 9.0R3/9.1R1 y posteriores, es susceptible a una vulnerabilidad de omisi\u00f3n de autenticaci\u00f3n expuesta por las funciones de Windows File Share Browser y Pulse Secure Collaboration de Pulse Connect Secure, que pueden permitir a un usuario no autenticado llevar a cabo una ejecuci\u00f3n de c\u00f3digo remoto arbitrario en Pulse Connect Secure gateway. Esta vulnerabilidad ha sido explotado en el wild"
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "CHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"availabilityImpact": "HIGH",
"baseScore": 10.0,
"baseSeverity": "CRITICAL"
},
"exploitabilityScore": 3.9,
"impactScore": 6.0
}
],
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "PARTIAL",
"availabilityImpact": "PARTIAL",
"baseScore": 7.5
},
"baseSeverity": "HIGH",
"exploitabilityScore": 10.0,
"impactScore": 6.4,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-416"
}
]
},
{
"source": "support@hackerone.com",
"type": "Secondary",
"description": [
{
"lang": "en",
"value": "CWE-287"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:pulsesecure:pulse_connect_secure:9.0:-:*:*:*:*:*:*",
"matchCriteriaId": "B474146F-7BE2-4A54-9CFC-60EB0E5F27FC"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:pulsesecure:pulse_connect_secure:9.0:r1:*:*:*:*:*:*",
"matchCriteriaId": "094AABE5-64DD-4F73-A22F-EB7DA26683A4"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:pulsesecure:pulse_connect_secure:9.0:r2:*:*:*:*:*:*",
"matchCriteriaId": "886CC874-9FE0-437B-B36E-4C83995895F3"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:pulsesecure:pulse_connect_secure:9.0:r2.1:*:*:*:*:*:*",
"matchCriteriaId": "42855E8B-09E4-4E3F-B5D4-C898E4BFA8A5"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:pulsesecure:pulse_connect_secure:9.0:r3:*:*:*:*:*:*",
"matchCriteriaId": "12EECBE5-8AEE-4373-889B-FA46DDCC1E82"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:pulsesecure:pulse_connect_secure:9.0:r3.1:*:*:*:*:*:*",
"matchCriteriaId": "8F7727DA-DEFD-4668-AE05-A662D6D98D92"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:pulsesecure:pulse_connect_secure:9.0:r3.2:*:*:*:*:*:*",
"matchCriteriaId": "7C9B3D17-9ED6-4B6A-9114-562F11552BA6"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:pulsesecure:pulse_connect_secure:9.0:r3.3:*:*:*:*:*:*",
"matchCriteriaId": "FABDF4EA-44B3-4196-A365-68DB4AB50A8A"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:pulsesecure:pulse_connect_secure:9.0:r3.5:*:*:*:*:*:*",
"matchCriteriaId": "959C0D51-06EC-4FF5-A50C-AFEB279A57BF"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:pulsesecure:pulse_connect_secure:9.0:r4:*:*:*:*:*:*",
"matchCriteriaId": "92C03D1C-7F66-4AF8-A208-591332D07157"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:pulsesecure:pulse_connect_secure:9.0:r4.1:*:*:*:*:*:*",
"matchCriteriaId": "B744C8B1-15FF-4283-9BD9-AD454403A8F7"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:pulsesecure:pulse_connect_secure:9.0:r5.0:*:*:*:*:*:*",
"matchCriteriaId": "FDAB8E47-5D89-4A45-BBD5-E5D87708E3C8"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:pulsesecure:pulse_connect_secure:9.0:r6.0:*:*:*:*:*:*",
"matchCriteriaId": "441BC346-77E3-4C54-9F98-DC008E1463AB"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:pulsesecure:pulse_connect_secure:9.1:-:*:*:*:*:*:*",
"matchCriteriaId": "8E84076A-C4AB-4C41-B325-F9557080E95A"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:pulsesecure:pulse_connect_secure:9.1:r1:*:*:*:*:*:*",
"matchCriteriaId": "1252710D-3A38-4C4D-8B97-1CEB6668A67B"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:pulsesecure:pulse_connect_secure:9.1:r10.0:*:*:*:*:*:*",
"matchCriteriaId": "A7198897-DA21-4E8C-B32F-0036300B2C66"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:pulsesecure:pulse_connect_secure:9.1:r10.2:*:*:*:*:*:*",
"matchCriteriaId": "63161280-A39B-463A-BCA2-DBAA44E8C4E4"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:pulsesecure:pulse_connect_secure:9.1:r11.0:*:*:*:*:*:*",
"matchCriteriaId": "575E6DC1-9EEF-40A7-8B78-E88AA9536340"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:pulsesecure:pulse_connect_secure:9.1:r11.1:*:*:*:*:*:*",
"matchCriteriaId": "9E7214B7-3289-41DA-A3A7-FACFD0241EEE"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:pulsesecure:pulse_connect_secure:9.1:r11.3:*:*:*:*:*:*",
"matchCriteriaId": "BCBD2F13-C156-46B4-A5FB-FD23D5076E56"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:pulsesecure:pulse_connect_secure:9.1:r2:*:*:*:*:*:*",
"matchCriteriaId": "C272B0B1-A08A-46D9-A8FB-5B2CF0C70A94"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:pulsesecure:pulse_connect_secure:9.1:r3:*:*:*:*:*:*",
"matchCriteriaId": "002F211E-954E-4881-80B1-D92C77A3687D"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:pulsesecure:pulse_connect_secure:9.1:r4:*:*:*:*:*:*",
"matchCriteriaId": "648BE1FA-7B29-416E-B827-25941170AB32"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:pulsesecure:pulse_connect_secure:9.1:r4.1:*:*:*:*:*:*",
"matchCriteriaId": "DFE6AF6A-F6C4-4463-8316-5BAB9A13452F"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:pulsesecure:pulse_connect_secure:9.1:r4.2:*:*:*:*:*:*",
"matchCriteriaId": "79B29059-9C55-455F-8B96-525BCF4E1DFE"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:pulsesecure:pulse_connect_secure:9.1:r4.3:*:*:*:*:*:*",
"matchCriteriaId": "69567696-0EED-425F-B6E9-86DE4CF6F4A5"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:pulsesecure:pulse_connect_secure:9.1:r5:*:*:*:*:*:*",
"matchCriteriaId": "C17EC167-CA23-47DD-9403-9087376963E9"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:pulsesecure:pulse_connect_secure:9.1:r6:*:*:*:*:*:*",
"matchCriteriaId": "47BCB978-25F4-4B31-9806-B3458962DC91"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:pulsesecure:pulse_connect_secure:9.1:r7:*:*:*:*:*:*",
"matchCriteriaId": "B4FB8381-79D4-42F4-910F-C574F8F0D322"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:pulsesecure:pulse_connect_secure:9.1:r8:*:*:*:*:*:*",
"matchCriteriaId": "96E3A807-BCFB-4A19-90D3-BDB3A5A36161"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:pulsesecure:pulse_connect_secure:9.1:r8.1:*:*:*:*:*:*",
"matchCriteriaId": "A8762030-CFCE-4524-9DB1-8C4796C1A885"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:pulsesecure:pulse_connect_secure:9.1:r8.2:*:*:*:*:*:*",
"matchCriteriaId": "333A0F57-87A7-459D-8CA3-2CBED3219B78"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:pulsesecure:pulse_connect_secure:9.1:r8.4:*:*:*:*:*:*",
"matchCriteriaId": "CEA21BBB-F2F3-4B25-8F52-5B25DA0D49DA"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:pulsesecure:pulse_connect_secure:9.1:r9:*:*:*:*:*:*",
"matchCriteriaId": "4825004D-60A3-4E36-890E-2CDFB20FC726"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:pulsesecure:pulse_connect_secure:9.1:r9.1:*:*:*:*:*:*",
"matchCriteriaId": "96352DBB-92FD-44DE-8820-9931CF926C8C"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:pulsesecure:pulse_connect_secure:9.1:r9.2:*:*:*:*:*:*",
"matchCriteriaId": "8DDFCAAC-B447-425E-967C-AA0A93860B9E"
}
]
}
]
}
],
"references": [
{
"url": "https://blog.pulsesecure.net/pulse-connect-secure-security-update/",
"source": "support@hackerone.com",
"tags": [
"Vendor Advisory"
]
},
{
"url": "https://kb.cert.org/vuls/id/213092",
"source": "support@hackerone.com",
"tags": [
"Third Party Advisory",
"US Government Resource"
]
},
{
"url": "https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44784/",
"source": "support@hackerone.com",
"tags": [
"Vendor Advisory"
]
},
{
"url": "https://www.fireeye.com/blog/threat-research/2021/04/suspected-apt-actors-leverage-bypass-techniques-pulse-secure-zero-day.html",
"source": "support@hackerone.com",
"tags": [
"Third Party Advisory"
]
}
]
}