7.2
CVE-2020-8260
- EPSS 96.48%
- Veröffentlicht 28.10.2020 13:15:13
- Zuletzt bearbeitet 30.10.2025 20:40:55
- Erkennungen
A vulnerability in the Pulse Connect Secure < 9.1R9 admin web interface could allow an authenticated attacker to perform an arbitrary code execution using uncontrolled gzip extraction.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ivanti ≫ Connect Secure Version <= 9.0
Ivanti ≫ Connect Secure Version 9.1 Update -
Ivanti ≫ Connect Secure Version 9.1 Update r1.0
Ivanti ≫ Connect Secure Version 9.1 Update r2.0
Ivanti ≫ Connect Secure Version 9.1 Update r3.0
Ivanti ≫ Connect Secure Version 9.1 Update r4.0
Ivanti ≫ Connect Secure Version 9.1 Update r4.1
Ivanti ≫ Connect Secure Version 9.1 Update r4.2
Ivanti ≫ Connect Secure Version 9.1 Update r4.3
Ivanti ≫ Connect Secure Version 9.1 Update r5.0
Ivanti ≫ Connect Secure Version 9.1 Update r6.0
Ivanti ≫ Connect Secure Version 9.1 Update r7.0
Ivanti ≫ Connect Secure Version 9.1 Update r8.0
Ivanti ≫ Connect Secure Version 9.1 Update r8.1
Ivanti ≫ Connect Secure Version 9.1 Update r8.2
Ivanti ≫ Connect Secure Version 9.1 Update r8.4
03.11.2021: CISA Known Exploited Vulnerabilities (KEV) Catalog
Ivanti Pulse Connect Secure Code Execution Vulnerability
SchwachstellePulse Connect Secure contains an unspecified vulnerability that allows an authenticated attacker to perform code execution using uncontrolled gzip extraction.
BeschreibungApply updates per vendor instructions.
Erforderliche Maßnahmen| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 96.48% | 0.999 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.2 | 1.2 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
|
| NIST | 6.5 | 8 | 6.4 |
AV:N/AC:L/Au:S/C:P/I:P/A:P
|
| CISA-ADP | 7.2 | 1.2 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
|
CWE-434 Unrestricted Upload of File with Dangerous Type
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44601
http://packetstormsecurity.com/files/160619/Pulse-Secure-VPN-Remote-Code-Execution.html
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-8260