Networking-Forums.com

Professional Discussions => Vendor Advisories => Topic started by: Netwörkheäd on January 10, 2020, 12:01:26 PM

Title: US-CERT- AA20-010A: Continued Exploitation of Pulse Secure VPN Vulnerability
Post by: Netwörkheäd on January 10, 2020, 12:01:26 PM
AA20-010A: Continued Exploitation of Pulse Secure VPN Vulnerability

Original release date: January 10, 2020

Summary

Unpatched Pulse Secure VPN servers continue to be an attractive target for malicious actors. Affected organizations that have not applied the software patch to fix a remote code execution (RCE) vulnerability, known as CVE-2019-11510, can become compromised in an attack. [1]



Although Pulse Secure [2] disclosed the vulnerability and provided software patches for the various affected products in April 2019, the Cybersecurity and Infrastructure Security Agency (CISA) continues to observe wide exploitation of CVE-2019-11510. [3] [4] [5]



CISA expects to see continued attacks exploiting unpatched Pulse Secure VPN environments and strongly urges users and administrators to upgrade to the corresponding fixes. [6]



Timelines of Specific Events




Technical Details

Impact



A remote, unauthenticated attacker may be able to compromise a vulnerable VPN server. The attacker may be able to gain access to all active users and their plain-text credentials. It may also be possible for the attacker to execute arbitrary commands on each VPN client as it successfully connects to the VPN server.



Affected versions:




Mitigations

This vulnerability has no viable workarounds except for applying the patches provided by the vendor and performing required system updates.



CISA strongly urges users and administrators to upgrade to the corresponding fixes. [7]


                   

References


                   

Revisions





           

This product is provided subject to this Notification and this Privacy & Use policy.





Source: AA20-010A: Continued Exploitation of Pulse Secure VPN Vulnerability (https://www.us-cert.gov/ncas/alerts/aa20-010a)