CRITICAL🇵🇱 Wersja polska

CVE-2018-20810

CVSS 9.8v3.0pub. 2019-06-28upd. 2024-11-21

Session data between cluster nodes during cluster synchronization is not properly encrypted in Pulse Secure Pulse Connect Secure (PCS) 8.3RX before 8.3R2 and Pulse Policy Secure (PPS) 5.4RX before 5.4R2. This is not applicable to PCS 8.1RX, PPS 5.2RX, or stand-alone devices.

CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Ivanti Connect Secure

    APP
    Ivanti
    8.3
  • Pulsesecure Pulse Policy Secure

    APP
    Pulsesecure
    5.4
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2025-22457CRITICAL9.0⚠ KEVPL ✓same product

Stack-based buffer overflow w Ivanti Connect Secure, Policy Secure i ZTA Gateways umożliwiający RCE

CVE-2025-0282CRITICAL9.0⚠ KEVPL ✓same product

Stack-based buffer overflow RCE w Ivanti Connect Secure, Policy Secure i Neurons for ZTA

CVE-2024-21887CRITICAL9.1⚠ KEVPL ✓same product

Command injection w Ivanti Connect Secure i Policy Secure — RCE jako administrator

CVE-2021-22893CRITICAL10.0⚠ KEVPL ✓same product

Ivanti/Pulse Connect Secure — krytyczny auth bypass umożliwiający RCE

CVE-2019-11510CRITICAL10.0⚠ KEVPL ✓same product

Krytyczny path traversal w Pulse Connect Secure — odczyt dowolnych plików bez uwierzytelnienia