High severity8.8NVD Advisory· Published Aug 29, 2017· Updated May 13, 2026
CVE-2017-11455
CVE-2017-11455
Description
diag.cgi in Pulse Connect Secure 8.2R1 through 8.2R5, 8.1R1 through 8.1R10 and Pulse Policy Secure 5.3R1 through 5.3R5, 5.2R1 through 5.2R8, and 5.1R1 through 5.1R10 allow remote attackers to hijack the authentication of administrators for requests to start tcpdump, related to the lack of anti-CSRF tokens.
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- www.securityfocus.com/bid/100530nvdThird Party AdvisoryVDB Entry
- www.securitytracker.com/id/1039242nvdThird Party AdvisoryVDB Entry
- kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA40793nvdVendor Advisory
News mentions
0No linked articles in our index yet.