Skip to main content

2019-129: Recommendations to mitigate vulnerability in Pulse Connect Secure VPN Software

The Australian Cyber Security Centre recommends users of the affected Pulse Connect Secure VPN software immediately upgrade their software.

Pulse Secure Logo

Upgrade to the corresponding versions as detailed in Pulse Secure Advisory https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44101/. The Australian Cyber Security Centre will continue to monitor and provide additional updates as required.

If an organisation believes it has been compromised they should:

  • Reset all Remote Access Passwords.
  • Check the Pulse Connect Secure VPN logon script configuration to ensure no malicious changes have been made.
  • Regenerate certificates for the Pulse Connect Secure VPN device.

The UK National Cyber Security Centre have also released an alert containing information on the exploitation of vulnerabilities in VPNs, including Pulse Connect Secure. Their information and mitigation advice is available at https://www.ncsc.gov.uk/news/alert-vpn-vulnerabilities  

References