First published: Fri Apr 26 2019(Updated: )
In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, and 8.2RX before 8.2R12.1, users using SAML authentication with the Reuse Existing NC (Pulse) Session option may see authentication leaks.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ivanti Connect Secure (ICS) VPN | =8.2 | |
Ivanti Connect Secure (ICS) VPN | =8.3 | |
Pulse Secure Pulse Connect Secure | =8.2r1.0 | |
Pulse Secure Pulse Connect Secure | =8.2r1.1 | |
Pulse Secure Pulse Connect Secure | =8.2r2.0 | |
Pulse Secure Pulse Connect Secure | =8.2r3.0 | |
Pulse Secure Pulse Connect Secure | =8.2r3.1 | |
Pulse Secure Pulse Connect Secure | =8.2r4.0 | |
Pulse Secure Pulse Connect Secure | =8.2r4.1 | |
Pulse Secure Pulse Connect Secure | =8.2r5.0 | |
Pulse Secure Pulse Connect Secure | =8.2r5.1 | |
Pulse Secure Pulse Connect Secure | =8.2r6.0 | |
Pulse Secure Pulse Connect Secure | =8.2r7.0 | |
Pulse Secure Pulse Connect Secure | =8.2r7.1 | |
Pulse Secure Pulse Connect Secure | =8.2rx | |
Pulse Secure Pulse Connect Secure | =8.3rx | |
Pulse Secure Pulse Connect Secure | =9.0r1 | |
Pulse Secure Pulse Connect Secure | =9.0r2 | |
Pulse Secure Pulse Connect Secure | =9.0r2.1 | |
Pulse Secure Pulse Connect Secure | =9.0r3 | |
Pulse Secure Pulse Connect Secure | =9.0r3.1 | |
Pulse Secure Pulse Connect Secure | =9.0r3.2 | |
Pulse Secure Pulse Connect Secure | =9.0rx | |
Pulse Secure Pulse Connect Secure | =8.2 | |
Pulse Secure Pulse Connect Secure | =8.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-11541 is a vulnerability in Pulse Secure Pulse Connect Secure that allows authentication leaks.
CVE-2019-11541 has a severity rating of 7.5 (High).
CVE-2019-11541 affects Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, and 8.2RX before 8.2R12.1.
SAML authentication with the Reuse Existing NC (Pulse) Session option is a feature in Pulse Secure Pulse Connect Secure that may be used by users.
To fix CVE-2019-11541, it is recommended to update to Pulse Connect Secure version 9.0R3.4, 8.3R7.1, or 8.2R12.1.