Junglewise Threat Intelligence

CVE-2020-8218: Pulse Connect Secure Code Injection Vulnerability

CVE-2020-8218 · Severity: critical · CVSS 7.2 · Exploited in the wild · Published 2022-03-07

Technologies: Ivanti Connect Secure. Vendors: Ivanti.

Executive brief

A code injection vulnerability in Pulse Connect Secure (now Ivanti Connect Secure) allows an authenticated administrator to execute arbitrary code by crafting a specific URI via the admin web interface. The vulnerability affects versions prior to 9.1R8 and has been observed being exploited in the wild.

Affected products

  • Pulse Secure Pulse Connect Secure < 9.1R8
  • Ivanti Connect Secure < 9.1R8

Timeline

  • 2020-11-13: disclosed: Public blog post detailing the vulnerability published by GoSecure.
  • 2022-03-07: kev added: Added to CISA's Known Exploited Vulnerabilities (KEV) catalog.