7.8

CVE-2020-8240

A vulnerability in the Pulse Secure Desktop Client < 9.1R9 allows a restricted user on an endpoint machine can use system-level privileges if the Embedded Browser is configured with Credential Provider. This vulnerability only affects Windows PDC if the Embedded Browser is configured with the Credential Provider.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Pulsesecure ≫ Pulse Secure Desktop Client SwPlatform windows Version < 9.1
Pulsesecure ≫ Pulse Secure Desktop Client Version 9.1 Update r1 SwPlatform windows
Pulsesecure ≫ Pulse Secure Desktop Client Version 9.1 Update r2 SwPlatform windows
Pulsesecure ≫ Pulse Secure Desktop Client Version 9.1 Update r3 SwPlatform windows
Pulsesecure ≫ Pulse Secure Desktop Client Version 9.1 Update r3.1 SwPlatform windows
Pulsesecure ≫ Pulse Secure Desktop Client Version 9.1 Update r4 SwPlatform windows
Pulsesecure ≫ Pulse Secure Desktop Client Version 9.1 Update r4.1 SwPlatform windows
Pulsesecure ≫ Pulse Secure Desktop Client Version 9.1 Update r4.2 SwPlatform windows
Pulsesecure ≫ Pulse Secure Desktop Client Version 9.1 Update r5 SwPlatform windows
Pulsesecure ≫ Pulse Secure Desktop Client Version 9.1 Update r6 SwPlatform windows
Pulsesecure ≫ Pulse Secure Desktop Client Version 9.1 Update r7 SwPlatform windows
Pulsesecure ≫ Pulse Secure Desktop Client Version 9.1 Update r7.1 SwPlatform windows
Pulsesecure ≫ Pulse Secure Desktop Client Version 9.1 Update r8 SwPlatform windows
Pulsesecure ≫ Pulse Secure Desktop Client Version 9.1 Update r8.2 SwPlatform windows
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.33% 0.248
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
NIST 6.9 3.4 10
AV:L/AC:M/Au:N/C:C/I:C/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44601
Vendor Advisory