Reset Search



SA40208 - [Pulse Secure] Single specific file content disclosure issue (CVE-2016-4788)

« Go Back


Product AffectedPulse Connect Secure
An issue was discovered with the Pulse Connect Secure device that could allow an attacker to print out contents from a specific file. The file contents do not contain any configuration details, but rather the contents of the system file itself. This issue was assigned: CVE-2016-4788.

This issue was responsibly reported to Pulse Secure by a security researcher. 

Pulse Secure is not aware of any public exploitation of this issue. 
This issue is resolved in PCS 8.2r1, 8.1r2, 8.0r10, and 7.4r13.4. 

Software downloads can be located on our support site:
There are no work arounds for this issue. The only way to resolve the issue is to upgrade to a fixed release of software. 
Related Links
CVSS Score5.8 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
Risk Assessment
This vulnerability was discovered and responsibly reported to Pulse Secure by Travis Emmert from the Product Security Team.
Alert TypeSA - Security Advisory
Risk LevelHigh
Attachment 1 
Attachment 2 
Legacy ID



Was this article helpful?



Please tell us how we can make this article more useful.

Characters Remaining: 255