CVE-2017-11196: Pulse Secure Pulse Connect Secure
High severity, CVSS 8.8. EPSS: 0.6% chance of exploitation in the next 30 days.
Pulse Connect Secure 8.3R1 has CSRF in logout.cgi. The logout function of the admin panel is not protected by any CSRF tokens, thus allowing an attacker to logout a user by making them visit a malicious web page.
Affected products
- Pulse Secure Pulse Connect Secure: version 8.3r1.0 only
Published 2017-07-12. Last modified 2026-06-17.