CVE-2020-8260
CVE Published | 2020-10-28 |
---|---|
Related CWE(s) | CWE-434: Unrestricted Upload of File with Dangerous Type |
Related Vendor(s) | pulsesecure |
Related Product(s) | pulse_secure_desktop_client |
Exploitation Reported (CISA KEV) | 2021-11-03 |
CVSS 3 Base Score | 7.2 (HIGH) |
CVSS 3 Attack Complexity | LOW |
CVSS 3 Attack Vector | NETWORK |
A vulnerability in the Pulse Connect Secure < 9.1R9 admin web interface could allow an authenticated attacker to perform an arbitrary code execution using uncontrolled gzip extraction.
Cyber Threat Graph Context
Explore how this CVE relates to the wider threat graph