CVE-2020-8218

CVE Published 2020-07-30
Related CWE(s) CWE-94: Improper Control of Generation of Code ('Code Injection')
Related Vendor(s) pulsesecure, ivanti
Related Product(s) connect_secure, pulse_policy_secure, pulse_connect_secure, policy_secure
Exploitation Reported (CISA KEV) 2022-03-07
CVSS 3 Base Score 7.2 (HIGH)
CVSS 3 Attack Complexity LOW
CVSS 3 Attack Vector NETWORK

A code injection vulnerability exists in Pulse Connect Secure <9.1R8 that allows an attacker to crafted a URI to perform an arbitrary code execution via the admin web interface.

Cyber Threat Graph Context

Explore how this CVE relates to the wider threat graph

Associated CAPEC Patterns

References