6.8
CVSSv2

CVE-2017-11193

Published: 12/07/2017 Updated: 20/07/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Pulse Connect Secure 8.3R1 has CSRF in diag.cgi. In the panel, the diag.cgi file is responsible for running commands such as ping, ping6, traceroute, traceroute6, nslookup, arp, and Portprobe. These functions do not have any protections against CSRF. That can allow an malicious user to run these commands against any IP if they can get an admin to visit their malicious CSRF page.

Vulnerable Product Search on Vulmon Subscribe to Product

pulsesecure pulse connect secure 8.3r1.0