
Definitely amazing work, but the RCE vulnerability they exploited was the post-auth admin RCE CVE-2019-11539, not the memory corruption (CVE-2019-11542): https://x.com/i/chat https://devco.re/blog/2019/09/02/attacking-ssl-vpn-part-3-the-golden-Pulse-Secure-ssl-vpn-rce-chain-with-Twitter-as-case-study/ You can see in the blog post how they needed to crack the hash in order to exploit the RCE. In fact, we gave Orange Tsai a Pwnie Award in 2019 for this exact work (I co-founded the pwnie awards and was still involved with them back then).
