ZeroHour

CVE-2020-8243

KEVlarge

Authenticated Arbitrary Code Execution via Template Upload in Ivanti Pulse Connect Secure

CISA: Ivanti Pulse Connect Secure Code Execution Vulnerability

CVSS 3.1
7.2 high
EPSS
91%p100
Published
()
KEV added
AI analysis

CVE-2020-8243 is a code injection flaw (CWE-94) in the administrator web interface of Ivanti Pulse Connect Secure versions prior to 9.1R8.2. An authenticated attacker with administrative privileges can upload a custom template through the admin interface, which results in arbitrary code execution on the appliance. Successful exploitation gives the attacker full control over the VPN gateway, including access to network traffic, stored credentials, and a foothold for pivoting into the internal network. Any organization running an affected Pulse Connect Secure version is exposed, and administrators should note the flaw requires admin-level access, which lowers risk when the management interface is not reachable by untrusted users. The vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03) and carries a very high EPSS score of about 91%, indicating active or highly likely exploitation; Pulse Secure VPN appliances broadly were also the target of APT exploitation activity in 2021.

What to do: Upgrade Pulse Connect Secure to 9.1R8.2 or later per the vendor's instructions, as required by the CISA KEV listing. Restrict the admin web interface to trusted management networks and review appliances for suspicious custom templates, modified configurations, or added administrator accounts, since Pulse Secure devices have been a documented target of APT intrusion tooling.

Affected
Ivanti Pulse Connect Secure< 9.1R8.2
Ivanti Pulse Policy Secure
Estimated exposure
largetens of thousands of internet-exposed Pulse Connect Secure appliances (~20,000–30,000+ in public scans), with far more deployed for internal/remote access — Public internet-wide scans around the 2021 Pulse Secure exploitation wave showed on the order of 20,000–30,000 Pulse Connect Secure appliances reachable from the internet, and the product's large installed base of enterprise VPN…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability in the Pulse Connect Secure < 9.1R8.2 admin web interface could allow an authenticated attacker to upload custom template to perform an arbitrary code execution.

CISA Known Exploited Vulnerability
Affected
Ivanti Pulse Connect Secure
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
ivanti
Products
connect secure, policy secure
Weakness
CWE-94
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news