HIGH
CVE-2020-8218
CVSS
7.2
KEV
Description
A code injection vulnerability exists in Pulse Connect Secure <9.1R8 that allows an attacker to crafted a URI to perform an arbitrary code execution via the admin web interface.
Summary dbcve.org
A code injection vulnerability in Pulse Connect Secure versions before 9.1R8 allows authenticated or unauthenticated attackers (description suggests web interface access) to execute arbitrary code by submitting a specially crafted URI to the admin web interface.
Mitigation
Upgrade Pulse Connect Secure to version 9.1R8 or later to remediate the code injection vulnerability. If immediate upgrade is not possible, restrict access to the admin web interface to trusted networks only.
Weakness (CWE)
CWE-94
Code Injection
EPSS Score
32.25%
Probability of exploitation in next 30 days
98.3th percentile
References
https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44516
Vendor Advisory
https://www.gosecure.net/blog/2020/11/13/forget-your-perimeter-part-2-four-vulnerabilities-in-pulse-connect-secure/
Exploit, Third Party Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-8218
US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.