7.2
CVE-2020-8218
- EPSS 32.25%
- Veröffentlicht 30.07.2020 13:15:11
- Zuletzt bearbeitet 30.10.2025 20:41:02
- Erkennungen
A code injection vulnerability exists in Pulse Connect Secure <9.1R8 that allows an attacker to crafted a URI to perform an arbitrary code execution via the admin web interface.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ivanti ≫ Connect Secure Version <= 9.0
Ivanti ≫ Connect Secure Version 9.1 Update -
Ivanti ≫ Connect Secure Version 9.1 Update r1
Ivanti ≫ Connect Secure Version 9.1 Update r2
Ivanti ≫ Connect Secure Version 9.1 Update r3
Ivanti ≫ Connect Secure Version 9.1 Update r4
Ivanti ≫ Connect Secure Version 9.1 Update r4.1
Ivanti ≫ Connect Secure Version 9.1 Update r4.2
Ivanti ≫ Connect Secure Version 9.1 Update r4.3
Ivanti ≫ Connect Secure Version 9.1 Update r5
Ivanti ≫ Connect Secure Version 9.1 Update r6
Ivanti ≫ Connect Secure Version 9.1 Update r7
Ivanti ≫ Policy Secure Version 9.1 Update -
Ivanti ≫ Policy Secure Version 9.1 Update r1
Ivanti ≫ Policy Secure Version 9.1 Update r2
Ivanti ≫ Policy Secure Version 9.1 Update r3
Ivanti ≫ Policy Secure Version 9.1 Update r3.1
Ivanti ≫ Policy Secure Version 9.1 Update r4
Ivanti ≫ Policy Secure Version 9.1 Update r4.1
Ivanti ≫ Policy Secure Version 9.1 Update r4.2
Ivanti ≫ Policy Secure Version 9.1 Update r5
Ivanti ≫ Policy Secure Version 9.1 Update r6
Ivanti ≫ Policy Secure Version 9.1 Update r7
Pulsesecure ≫ Pulse Policy Secure Version <= 9.0
07.03.2022: CISA Known Exploited Vulnerabilities (KEV) Catalog
Pulse Connect Secure Code Injection Vulnerability
SchwachstelleA code injection vulnerability exists in Pulse Connect Secure that allows an attacker to crafted a URI to perform an arbitrary code execution via the admin web interface.
BeschreibungApply updates per vendor instructions.
Erforderliche Maßnahmen| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 32.25% | 0.981 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.2 | 1.2 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
|
| NIST | 6.5 | 8 | 6.4 |
AV:N/AC:L/Au:S/C:P/I:P/A:P
|
| CISA-ADP | 7.2 | 1.2 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
|
CWE-94 Improper Control of Generation of Code ('Code Injection')
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44516
https://www.gosecure.net/blog/2020/11/13/forget-your-perimeter-part-2-four-vulnerabilities-in-pulse-connect-secure/
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-8218