CVE-2020-8243
KEVlargeAuthenticated Arbitrary Code Execution via Template Upload in Ivanti Pulse Connect Secure
CISA: Ivanti Pulse Connect Secure Code Execution Vulnerability
CVE-2020-8243 is a code injection flaw (CWE-94) in the administrator web interface of Ivanti Pulse Connect Secure versions prior to 9.1R8.2. An authenticated attacker with administrative privileges can upload a custom template through the admin interface, which results in arbitrary code execution on the appliance. Successful exploitation gives the attacker full control over the VPN gateway, including access to network traffic, stored credentials, and a foothold for pivoting into the internal network. Any organization running an affected Pulse Connect Secure version is exposed, and administrators should note the flaw requires admin-level access, which lowers risk when the management interface is not reachable by untrusted users. The vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03) and carries a very high EPSS score of about 91%, indicating active or highly likely exploitation; Pulse Secure VPN appliances broadly were also the target of APT exploitation activity in 2021.
What to do: Upgrade Pulse Connect Secure to 9.1R8.2 or later per the vendor's instructions, as required by the CISA KEV listing. Restrict the admin web interface to trusted management networks and review appliances for suspicious custom templates, modified configurations, or added administrator accounts, since Pulse Secure devices have been a documented target of APT intrusion tooling.
| Ivanti Pulse Connect Secure | < 9.1R8.2 |
| Ivanti Pulse Policy Secure | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability in the Pulse Connect Secure < 9.1R8.2 admin web interface could allow an authenticated attacker to upload custom template to perform an arbitrary code execution.
- Affected
- Ivanti Pulse Connect Secure
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- ivanti
- Products
- connect secure, policy secure
- Weakness
- CWE-94
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H