In Ivanti Pulse Secure Pulse Connect Secure (PCS) before...
High severity
Unreviewed
Published
Aug 13, 2022
to the GitHub Advisory Database
•
Updated Jan 28, 2023
Description
Published by the National Vulnerability Database
Aug 12, 2022
Published to the GitHub Advisory Database
Aug 13, 2022
Last updated
Jan 28, 2023
In Ivanti Pulse Secure Pulse Connect Secure (PCS) before 9.1R12, the administrator password is stored in the HTML source code of the "Maintenance > Push Configuration > Targets > Target Name" targets.cgi screen. A read-only administrative user can escalate to a read-write administrative role.
References