CVE-2020-8260

CVE Published 2020-10-28
Related CWE(s) CWE-434: Unrestricted Upload of File with Dangerous Type
Related Vendor(s) pulsesecure
Related Product(s) pulse_secure_desktop_client
Exploitation Reported (CISA KEV) 2021-11-03
CVSS 3 Base Score 7.2 (HIGH)
CVSS 3 Attack Complexity LOW
CVSS 3 Attack Vector NETWORK

A vulnerability in the Pulse Connect Secure < 9.1R9 admin web interface could allow an authenticated attacker to perform an arbitrary code execution using uncontrolled gzip extraction.

Cyber Threat Graph Context

Explore how this CVE relates to the wider threat graph

Associated CAPEC Patterns

References