An issue was discovered in Pulse Secure Pulse Connect Secure (PCS) through 2020-04-06. The applet in tncc.jar, executed on macOS, Linux, and Solaris clients when a Host Checker policy is enforced, accepts an arbitrary SSL certificate.
The product does not validate, or incorrectly validates, a certificate.
Link | Tags |
---|---|
https://git.lsd.cat/g/pulse-host-checker-rce | third party advisory exploit |
https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44426 | vendor advisory |