HIGH

CVE-2020-8218

Ivanti Connect Secure 2020-07-30 CVSS v3.1
CVSS
7.2
KEV

Description

A code injection vulnerability exists in Pulse Connect Secure <9.1R8 that allows an attacker to crafted a URI to perform an arbitrary code execution via the admin web interface.

Summary dbcve.org

A code injection vulnerability in Pulse Connect Secure versions before 9.1R8 allows authenticated or unauthenticated attackers (description suggests web interface access) to execute arbitrary code by submitting a specially crafted URI to the admin web interface.

Mitigation

Upgrade Pulse Connect Secure to version 9.1R8 or later to remediate the code injection vulnerability. If immediate upgrade is not possible, restrict access to the admin web interface to trusted networks only.

Proof of Concept

Weakness (CWE)

CWE-94 Code Injection

EPSS Score

32.25%
Probability of exploitation in next 30 days
98.3th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE