CVE-2016-4792: Medium severity ivanti pulse connect secure vulnerability
Published May 26, 2016
·Updated
Pulse Connect Secure (PCS) 8.2 before 8.2r1 allows remote attackers to disclose sign in pages via unspecified vectors.
Affected Software
2 affected components
PulseSecure Pulse Connect Secure=8.2
Ivanti Connect Secure=8.2
Event History
May 26, 2016
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-4792?
CVE-2016-4792 has been assigned a severity score of 6.5, indicating it is of medium severity.
2
How do I fix CVE-2016-4792?
To mitigate CVE-2016-4792, upgrade Pulse Connect Secure to version 8.2r1 or later.
3
What impact does CVE-2016-4792 have on affected systems?
CVE-2016-4792 allows remote attackers to disclose sign-in pages, potentially exposing sensitive login information.
4
Which versions of Pulse Connect Secure are affected by CVE-2016-4792?
CVE-2016-4792 affects Pulse Connect Secure version 8.2 prior to 8.2r1.
5
Is there a workaround for CVE-2016-4792 while I prepare to apply the update?
There are no known effective workarounds for CVE-2016-4792, so upgrading is the recommended action.