Field Note on CVE-2019-11510: Pulse Connect Secure SSL-VPN in the Netherlands


연구 분야: Safety



학회: Digital Threats: Research and Practice , Volume 1, Issue 2


초록

This Field Note describes the case of a critical unauthenticated RCE vulnerability in an SSL-VPN product that remained unpatched at a large scale-up and until after exploits became public. Approximately 14,500 systems worldwide were reportedly unpatched at the end of August 2019. Two weeks after exploits emerged in public, both GCHQ and NSA released notices that the vulnerability was being exploited by APT actors. The present Field Note describes observations from the Netherlands and includes reflections in an attempt to stimulate thinking on how to improve the status quo, such as through coordinated proactive measures by CSIRTs.


Author Profile
Martijn Koot

Secura BV 8 University of Amsterdam CA Eindhoven

Bouvet Island

📄 논문 정보

발행 연도 2020년
인용수 2
출판 국가 Bouvet Island
사이트 ACM
좋아요 수 0