Session data between cluster nodes during cluster synchronization is not properly encrypted in Pulse Secure Pulse Connect Secure (PCS) 8.3RX before 8.3R2 and Pulse Policy Secure (PPS) 5.4RX before 5.4R2. This is not applicable to PCS 8.1RX, PPS 5.2RX, or stand-alone devices.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HIvanti Connect Secure
APPIvanti8.3Pulsesecure Pulse Policy Secure
APPPulsesecure5.4
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
Related vulnerabilities
CVE-2025-22457CRITICAL9.0⚠ KEVPL ✓same product
Stack-based buffer overflow w Ivanti Connect Secure, Policy Secure i ZTA Gateways umożliwiający RCE
CVE-2025-0282CRITICAL9.0⚠ KEVPL ✓same product
Stack-based buffer overflow RCE w Ivanti Connect Secure, Policy Secure i Neurons for ZTA
CVE-2024-21887CRITICAL9.1⚠ KEVPL ✓same product
Command injection w Ivanti Connect Secure i Policy Secure — RCE jako administrator
CVE-2021-22893CRITICAL10.0⚠ KEVPL ✓same product
Ivanti/Pulse Connect Secure — krytyczny auth bypass umożliwiający RCE
CVE-2019-11510CRITICAL10.0⚠ KEVPL ✓same product
Krytyczny path traversal w Pulse Connect Secure — odczyt dowolnych plików bez uwierzytelnienia