CVE-2020-8218
KEV PoC largeCode Injection RCE in Pulse Connect Secure Admin Web Interface
CISA: Pulse Connect Secure Code Injection Vulnerability
CVE-2020-8218 is a code injection vulnerability (CWE-94) in the admin web interface of Pulse Secure's Pulse Connect Secure SSL VPN appliance. An attacker triggers it by sending a specially crafted URI to the admin web interface, resulting in arbitrary code execution on the appliance. Successful exploitation gives the attacker code execution on the VPN gateway and a foothold from which internal networks behind the appliance could be reached. All organizations running Pulse Connect Secure are affected, particularly those whose admin web interface is reachable by untrusted users. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-07), confirming in-the-wild exploitation, and its 98th-percentile EPSS score (32.7% probability of exploitation within 30 days) indicates elevated risk; no public proof-of-concept is known.
What to do: Apply the latest Pulse Connect Secure maintenance update per the vendor's instructions, as required by the CISA KEV listing. Until patched, restrict the admin web interface to trusted management networks or jump hosts and review admin interface logs for unusual crafted-URI requests or signs of post-exploitation. Because ransomware use is listed as unknown, treat any unpatched, internet-reachable appliance as high priority for patching and compromise assessment.
| Pulse Secure Pulse Connect Secure | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A code injection vulnerability exists in Pulse Connect Secure <9.1R8 that allows an attacker to crafted a URI to perform an arbitrary code execution via the admin web interface.
- Affected
- Pulse Secure Pulse Connect Secure
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- ivantipulsesecure
- Products
- connect secure, policy secure, pulse policy secure
- Weakness
- CWE-94
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H