ZeroHour

CVE-2020-8218

KEV PoC large

Code Injection RCE in Pulse Connect Secure Admin Web Interface

CISA: Pulse Connect Secure Code Injection Vulnerability

CVSS 3.1
7.2 high
EPSS
33%p98
Published
()
KEV added
AI analysis

CVE-2020-8218 is a code injection vulnerability (CWE-94) in the admin web interface of Pulse Secure's Pulse Connect Secure SSL VPN appliance. An attacker triggers it by sending a specially crafted URI to the admin web interface, resulting in arbitrary code execution on the appliance. Successful exploitation gives the attacker code execution on the VPN gateway and a foothold from which internal networks behind the appliance could be reached. All organizations running Pulse Connect Secure are affected, particularly those whose admin web interface is reachable by untrusted users. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-07), confirming in-the-wild exploitation, and its 98th-percentile EPSS score (32.7% probability of exploitation within 30 days) indicates elevated risk; no public proof-of-concept is known.

What to do: Apply the latest Pulse Connect Secure maintenance update per the vendor's instructions, as required by the CISA KEV listing. Until patched, restrict the admin web interface to trusted management networks or jump hosts and review admin interface logs for unusual crafted-URI requests or signs of post-exploitation. Because ransomware use is listed as unknown, treat any unpatched, internet-reachable appliance as high priority for patching and compromise assessment.

Affected
Pulse Secure Pulse Connect Secure
Estimated exposure
largetens of thousands of internet-exposed Pulse Connect Secure appliances (public internet scans showed roughly 20,000-30,000+) — Pulse Connect Secure is a widely deployed enterprise SSL VPN with hundreds of thousands of historical deployments, and public internet-wide scans around 2020-2021 consistently observed tens of thousands of PCS appliances exposed, though…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A code injection vulnerability exists in Pulse Connect Secure <9.1R8 that allows an attacker to crafted a URI to perform an arbitrary code execution via the admin web interface.

CISA Known Exploited Vulnerability
Affected
Pulse Secure Pulse Connect Secure
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
ivantipulsesecure
Products
connect secure, policy secure, pulse policy secure
Weakness
CWE-94
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news