Pulse Secure VPN Vulnerability: What Businesses Need to Know

One of the ways in which many companies try to combat exploitation by hackers is through the use of a VPN (virtual private network). VPNs allow businesses to create what is essentially a private network where all the IP (internet protocol) addresses used by employees are hidden, thus allowing users to conduct online activity that is virtually untraceable.

While software companies that offer VPNs put forth great effort to design their VPNs in such a way as to be untouchable by hackers, occasionally vulnerabilities in their software are discovered. In the case of Pulse Secure’s popular Connect Secure and Policy Secure products, bugs were reported as early as April 2019.

In this post, we will outline the type of vulnerabilities discovered in these products, why these issues leave a company particularly vulnerable, as well as discuss the only solution available to resolve the issue.

How a Hacker Exploits Pulse Secure VPNs

According to CISA (the Cybersecurity and Infrastructure Security Agency), Pulse VPNs contain a vulnerability (CVE-2019-11510) that an unauthorized remote user may exploit in order to gain access to all active VPN users, as well as their passwords in plain text.

In addition, these remote attackers may steal data through remote arbitrary file access on a Pulse Connect Secure gateway, and/or they may deploy malware or ransomware after they successfully connect to the victim’s VPN server.

This particular vulnerability has been quite serious for some affected companies, as nation-state sponsored hackers managed to encrypt their data and/or expose other sensitive data to the public. Some companies who refused to pay the demanded ransoms have experienced these exact scenarios.

To make matters worse, the hackers publicly published information on how to perform the exploitation, thus providing even more fuel for large-scale scanning activity by other hackers searching for vulnerable systems.

A Slow User Response

While Pulse Secure issued an advisory regarding the issue on April 24, 2019 and released patches shortly thereafter for both their Connect Secure and Policy Secure versions, companies were somewhat slow to respond.

Even several months later in August of 2019, 14,000 systems worldwide, with one third of the systems located in the United States, were found to be still vulnerable to the bug. Even into January of 2020, multiple corporate attacks from this same bug had been reported.

The Only Solution

Any company using either of Pulse’s VPN products should check to make sure the patches sent out by Pulse Secure have been applied to their systems. Application of the patches is the only solution as there are no other workarounds or mitigation available.

Listed below are all the vulnerable software versions:

  • Pulse Connect Secure 9.0R1 – 9.0R3.3
  • Pulse Connect Secure 8.3R1 – 8.3R7
  • Pulse Connect Secure 8.2R1 – 8.2R12
  • Pulse Connect Secure 8.1R1 – 8.1R15
  • Pulse Policy Secure 9.0R1 – 9.0R3.1
  • Pulse Policy Secure 5.4R1 – 5.4R7
  • Pulse Policy Secure 5.3R1 – 5.3R12
  • Pulse Policy Secure 5.2R1 – 5.2R12
  • Pulse Policy Secure 5.1R1 – 5.1R15

Don’t Let an Unpatched VPN Expose Your Business

While most companies using these versions of Pulse software have been patched by now, the exploitation remains a serious one. The publicly available exploit code allows attackers to deploy ransomware on any systems that remain exposed.

Companies who have not yet applied the patch remain vulnerable to disclosure of sensitive corporate data and/or permanent encryption of their files if they refuse to pay the ransoms demanded by their attackers.

If your company uses either Pulse Connect Secure or Pulse Policy Secure VPN software and you are unsure whether this critical patch has been applied, WheelHouse IT can help. Our team conducts thorough vulnerability assessments to identify gaps in your security posture before attackers do, and our security and compliance services keep your business protected on an ongoing basis.

Contact us today or request a complimentary risk assessment — FL: (954) 474-2204 | NY: (516) 536-5006.