First published: Thu May 26 2016(Updated: )
Pulse Connect Secure (PCS) 8.2 before 8.2r1, 8.1 before 8.1r2, 8.0 before 8.0r10, and 7.4 before 7.4r13.4 allow remote attackers to read sensitive system authentication files in an unspecified directory via unknown vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ivanti Connect Secure (ICS) VPN | =8.0 | |
Ivanti Connect Secure (ICS) VPN | =8.2 | |
Pulse Secure Pulse Connect Secure | =7.4 | |
Ivanti Connect Secure (ICS) VPN | =8.1 | |
Pulse Secure Pulse Connect Secure | =8.1r1.0 | |
Pulse Secure Pulse Connect Secure | =8.0 | |
Pulse Secure Pulse Connect Secure | =8.2 | |
Pulse Secure Pulse Connect Secure | =8.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-4787 has a high severity rating due to its potential to allow remote attackers to read sensitive authentication files.
To fix CVE-2016-4787, upgrade to Pulse Connect Secure version 8.2r1, 8.1r2, 8.0r10, or 7.4r13.4 or later.
CVE-2016-4787 affects versions 8.2 before 8.2r1, 8.1 before 8.1r2, 8.0 before 8.0r10, and 7.4 before 7.4r13.4.
CVE-2016-4787 allows remote attackers to exploit the vulnerability to read sensitive system authentication files.
Yes, a patch is available by upgrading to the specified affected versions for Pulse Connect Secure.