Impact
Pulse contains a format-string vulnerability in the Quick Security Setup handler. The fmt.Sprintf function is called with a Username value supplied by a caller. Because no validation or sanitization is performed, malicious format specifiers can be embedded in that value. If an attacker sends such a request, the formatter will process the specifiers, potentially yielding remote code execution or leaking sensitive data from the server.
Affected Systems
Affected are rcourtman Pulse versions up to 6.0.4 and 6.1.0-rc.4. The vulnerability resides in the /api/security/quick-setup endpoint handled by the Quick Security Setup component.
Risk and Exploitability
The CVSS score of 9.4 indicates critical severity. EPSS is not available, so the real‑world exploitation probability cannot be quantified. The vulnerability is not listed in the CISA KEV catalog, yet the description explicitly states that the attack may be performed from remote hosts. Because the flaw results from improper input validation (CWE-20) and exploits the Go fmt.Sprintf implementation, remote attackers can inject format strings that cause code execution on the server. The vendor recommends upgrading to Pulse 6.1.0 or later to obtain the fix.
OpenCVE Enrichment