Junglewise Threat Intelligence

CVE-2020-8243: Ivanti Pulse Connect Secure Code Execution Vulnerability

CVE-2020-8243 · Severity: critical · CVSS 7.2 · Exploited in the wild · Published 2021-11-03

Vendors: Ivanti.

Executive brief

A vulnerability in the Ivanti Pulse Connect Secure admin web interface allows an authenticated attacker with high privileges to upload a custom template. This can be leveraged to achieve arbitrary code execution on the underlying system.

Affected products

  • Ivanti Pulse Connect Secure < 9.1R8.2
  • Ivanti Pulse Policy Secure < 9.1R8.2

Timeline

  • 2021-11-03: disclosed
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2021-11-03: advisory: NVD publication date