Show plain JSON{"id": "CVE-2017-11455", "cveTags": [], "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 6.8, "accessVector": "NETWORK", "vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P", "authentication": "NONE", "integrityImpact": "PARTIAL", "accessComplexity": "MEDIUM", "availabilityImpact": "PARTIAL", "confidentialityImpact": "PARTIAL"}, "acInsufInfo": false, "impactScore": 6.4, "baseSeverity": "MEDIUM", "obtainAllPrivilege": false, "exploitabilityScore": 8.6, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": true}], "cvssMetricV30": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"scope": "UNCHANGED", "version": "3.0", "baseScore": 8.8, "attackVector": "NETWORK", "baseSeverity": "HIGH", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "integrityImpact": "HIGH", "userInteraction": "REQUIRED", "attackComplexity": "LOW", "availabilityImpact": "HIGH", "privilegesRequired": "NONE", "confidentialityImpact": "HIGH"}, "impactScore": 5.9, "exploitabilityScore": 2.8}]}, "published": "2017-08-29T15:29:00.660", "references": [{"url": "http://www.securityfocus.com/bid/100530", "tags": ["Third Party Advisory", "VDB Entry"], "source": "cve@mitre.org"}, {"url": "http://www.securitytracker.com/id/1039242", "tags": ["Third Party Advisory", "VDB Entry"], "source": "cve@mitre.org"}, {"url": "https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA40793", "tags": ["Vendor Advisory"], "source": "cve@mitre.org"}, {"url": "http://www.securityfocus.com/bid/100530", "tags": ["Third Party Advisory", "VDB Entry"], "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://www.securitytracker.com/id/1039242", "tags": ["Third Party Advisory", "VDB Entry"], "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA40793", "tags": ["Vendor Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}], "vulnStatus": "Deferred", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "CWE-352"}]}], "descriptions": [{"lang": "en", "value": "diag.cgi in Pulse Connect Secure 8.2R1 through 8.2R5, 8.1R1 through 8.1R10 and Pulse Policy Secure 5.3R1 through 5.3R5, 5.2R1 through 5.2R8, and 5.1R1 through 5.1R10 allow remote attackers to hijack the authentication of administrators for requests to start tcpdump, related to the lack of anti-CSRF tokens."}, {"lang": "es", "value": "diag.cgi en Pulse Connect Secure 8.2R1 en su versi\u00f3n 8.2R5, 8.1R1 en su versi\u00f3n 8.1R10 y Pulse Policy Secure 5.3R1 en su versi\u00f3n 5.3R5, 5.2R1 en su versi\u00f3n 5.2R8, y 5.1R1 en su versi\u00f3n 5.1R10 permite que atacantes remotos secuestren la autenticaci\u00f3n de administradores para peticiones para poner en marcha tcpdump, relacionado con la falta de tokens anti-CSRF."}], "lastModified": "2025-04-20T01:37:25.860", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:ivanti:connect_secure:8.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "202E4839-7CE4-49CE-BEE1-CB33A96770E7"}, {"criteria": "cpe:2.3:a:pulsesecure:pulse_connect_secure:8.1r1.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E2037BE1-408C-47E8-8A70-8440BF3A1ED6"}, {"criteria": "cpe:2.3:a:pulsesecure:pulse_connect_secure:8.2r1.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D7369296-0C10-4B64-A0EC-2E7BFAC5BB40"}, {"criteria": "cpe:2.3:a:pulsesecure:pulse_connect_secure:8.2r1.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F13F586F-A5FA-424F-B172-14FC29402F59"}, {"criteria": "cpe:2.3:a:pulsesecure:pulse_connect_secure:8.2r2.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D6BE71A8-1C4A-4CE0-A78C-DCF72E6775BA"}, {"criteria": "cpe:2.3:a:pulsesecure:pulse_connect_secure:8.2r3.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "51E0AC17-77DE-440F-8166-FD3A8D039EB7"}, {"criteria": "cpe:2.3:a:pulsesecure:pulse_connect_secure:8.2r3.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2A7A8628-6636-485E-B888-A13D732D87C7"}, {"criteria": "cpe:2.3:a:pulsesecure:pulse_connect_secure:8.2r4.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8DB60BAE-D42E-4953-822D-C9B4CF83EA9D"}, {"criteria": "cpe:2.3:a:pulsesecure:pulse_connect_secure:8.2r4.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9A9BB556-DADF-49F0-BEF2-84629EC430FF"}, {"criteria": "cpe:2.3:a:pulsesecure:pulse_connect_secure:8.2r5.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E9AB1607-3B0C-49A8-95E0-68FB8DF6432B"}], "operator": "OR"}]}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:pulsesecure:pulse_policy_secure:5.1r1.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "45491FB0-2EDC-4B62-838F-A8CB2E92F4FD"}, {"criteria": "cpe:2.3:a:pulsesecure:pulse_policy_secure:5.1r1.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F62EC1F3-10DC-4387-B4DA-8EA8086EA390"}, {"criteria": "cpe:2.3:a:pulsesecure:pulse_policy_secure:5.1r2.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "75A2801C-029F-469C-9492-9AB0535B1F6C"}, {"criteria": "cpe:2.3:a:pulsesecure:pulse_policy_secure:5.1r2.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "219B113E-88AB-4250-81BB-3735A49A09C8"}, {"criteria": "cpe:2.3:a:pulsesecure:pulse_policy_secure:5.1r3.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "84885E71-5C0D-4869-97A5-B8F955FBE728"}, {"criteria": "cpe:2.3:a:pulsesecure:pulse_policy_secure:5.1r3.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D8F5AB09-D5D3-4499-BDE8-6471F827D825"}, {"criteria": "cpe:2.3:a:pulsesecure:pulse_policy_secure:5.1r4.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "09FF5E94-07F5-416C-976F-4FF22141A145"}, {"criteria": "cpe:2.3:a:pulsesecure:pulse_policy_secure:5.1r5.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E77318F9-AA30-4010-A351-98A3942DA8DD"}, {"criteria": "cpe:2.3:a:pulsesecure:pulse_policy_secure:5.1r6.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9D328C58-51A0-4A62-8CFC-BAA5A9D8EDF3"}, {"criteria": "cpe:2.3:a:pulsesecure:pulse_policy_secure:5.1r7.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F3015D79-3AD8-4EBE-A236-6ADEC2AA4B6C"}, {"criteria": "cpe:2.3:a:pulsesecure:pulse_policy_secure:5.1r7.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DDC948E7-4EC5-45E1-98A7-A940D05E3BC2"}, {"criteria": "cpe:2.3:a:pulsesecure:pulse_policy_secure:5.1r8.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A8BFFFF2-BA60-483A-BD7E-041EDD1932E3"}, {"criteria": "cpe:2.3:a:pulsesecure:pulse_policy_secure:5.1r9.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2A100AF1-A8A7-4E0A-9D29-E00C56C0AAFE"}, {"criteria": "cpe:2.3:a:pulsesecure:pulse_policy_secure:5.1r10:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FFE85EB6-035E-4158-92E5-C6D2543FBE1A"}, {"criteria": "cpe:2.3:a:pulsesecure:pulse_policy_secure:5.2r1.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6A42EFC8-C5FF-4397-87CF-263813FAA5D7"}, {"criteria": "cpe:2.3:a:pulsesecure:pulse_policy_secure:5.2r2.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C952B5B8-DCAB-476A-9E60-3F1BBE509F21"}, {"criteria": "cpe:2.3:a:pulsesecure:pulse_policy_secure:5.2r3.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7F199F01-9EEA-4184-AD99-6B21110484AB"}, {"criteria": "cpe:2.3:a:pulsesecure:pulse_policy_secure:5.2r3.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9938EBCC-B9B7-4FB1-9ACB-9BED485AB5E2"}, {"criteria": "cpe:2.3:a:pulsesecure:pulse_policy_secure:5.2r4.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9B4A309B-ACB0-4053-909A-6889129EB2C1"}, {"criteria": "cpe:2.3:a:pulsesecure:pulse_policy_secure:5.2r5.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D8A4A105-EBF3-4895-9ABE-50972DD232F8"}, {"criteria": "cpe:2.3:a:pulsesecure:pulse_policy_secure:5.2r6.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4013CA1C-48F0-46F6-B327-E6B34311A7EA"}, {"criteria": "cpe:2.3:a:pulsesecure:pulse_policy_secure:5.2r7.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "112B9736-336D-4C72-A960-0B33DD3439EF"}, {"criteria": "cpe:2.3:a:pulsesecure:pulse_policy_secure:5.2r7.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "49FA8DC5-900B-4A53-AF55-410A7FF901E9"}, {"criteria": "cpe:2.3:a:pulsesecure:pulse_policy_secure:5.2r8.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A4946BBE-E449-4F89-910C-3389BDF36071"}, {"criteria": "cpe:2.3:a:pulsesecure:pulse_policy_secure:5.3r1.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "94170224-C78B-458A-B63E-53E303B0DCE3"}, {"criteria": "cpe:2.3:a:pulsesecure:pulse_policy_secure:5.3r1.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "17449ADA-D4CC-4A23-9699-2D3E695C519A"}, {"criteria": "cpe:2.3:a:pulsesecure:pulse_policy_secure:5.3r2.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "44B21A8C-F09F-4286-8E32-C10E474C8D3F"}, {"criteria": "cpe:2.3:a:pulsesecure:pulse_policy_secure:5.3r3.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8654C226-F77A-464D-9AD1-010DC11F8C46"}, {"criteria": "cpe:2.3:a:pulsesecure:pulse_policy_secure:5.3r3.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "70F3AFCF-8723-4F80-89A2-BC9D62CE920E"}, {"criteria": "cpe:2.3:a:pulsesecure:pulse_policy_secure:5.3r4.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "545F18AB-635E-47C0-ACFE-8B2A849253FF"}, {"criteria": "cpe:2.3:a:pulsesecure:pulse_policy_secure:5.3r4.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "52DD6EDE-5CF1-4BD9-93B7-8100ED9DDC3F"}, {"criteria": "cpe:2.3:a:pulsesecure:pulse_policy_secure:5.3r5.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6D74E173-3599-4A32-BE9A-482998800122"}, {"criteria": "cpe:2.3:a:pulsesecure:pulse_policy_secure:5.3r5.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "116DD35E-B83E-4865-8B54-E5C68D148187"}, {"criteria": "cpe:2.3:a:pulsesecure:pulse_policy_secure:5.3r5.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7D02A7DF-69CE-426B-8153-3BA404B4AC64"}, {"criteria": "cpe:2.3:a:pulsesecure:pulse_policy_secure:5.3r6.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DA199898-3820-4B6C-ADF6-9EA0E8238200"}, {"criteria": "cpe:2.3:a:pulsesecure:pulse_policy_secure:5.3r7.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A37EBB8A-48E0-4092-A5E4-ABA0C02934AD"}, {"criteria": "cpe:2.3:a:pulsesecure:pulse_policy_secure:5.3r8.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9EAEBC16-AA55-4145-8FD4-84217DE4CB6D"}], "operator": "OR"}]}], "sourceIdentifier": "cve@mitre.org"}