CVE-2017-11196: Pulse Secure Pulse Connect Secure

High severity, CVSS 8.8. EPSS: 0.6% chance of exploitation in the next 30 days.

Pulse Connect Secure 8.3R1 has CSRF in logout.cgi. The logout function of the admin panel is not protected by any CSRF tokens, thus allowing an attacker to logout a user by making them visit a malicious web page.

Affected products

Published 2017-07-12. Last modified 2026-06-17.