CVE-2020-8260
KEV PoC massAuthenticated RCE in Ivanti Pulse Connect Secure admin web interface (pre-9.1R9)
CISA: Ivanti Pulse Connect Secure Code Execution Vulnerability
Ivanti Pulse Connect Secure versions before 9.1R9 contain a vulnerability (mapped to CWE-434) in the administrative web interface in which compressed uploads are handled with uncontrolled gzip extraction. An authenticated attacker with high-privilege (admin-level) access to that interface can send a crafted gzip-compressed file, triggering arbitrary code execution on the appliance with high impact to confidentiality, integrity, and availability (CVSS 3.1: 7.2, AV:N/PR:H). Successful exploitation yields arbitrary code execution on the VPN appliance itself, effectively enabling full compromise of the gateway that terminates the organization's VPN sessions. Any organization running Pulse Connect Secure on a release prior to 9.1R9 is affected, making the typical target an enterprise or government SSL VPN appliance accessible to anyone holding admin credentials. Exploitation is in the wild: the flaw is in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03), carries a 96.5% EPSS exploitation probability (100th percentile), and a public proof of concept is available.
What to do: Upgrade Pulse Connect Secure to 9.1R9 or later per the vendor's instructions; given the related patch-bypass flaw CVE-2021-22937 and the 'new urgent update' headlines, ensure the most recent available 9.1R release is applied rather than relying solely on the original 9.1R9 fix. Restrict the admin web interface to trusted management networks and review administrative accounts. Because the flaw is on CISA's KEV list and CISA has published malware analysis reports for Pulse Secure-targeted samples, hunt patched and unpatched devices for signs of compromise (e.g., web shells or implants).
| ivanti connect secure | all releases prior to 9.1R9 (< 9.1R9) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability in the Pulse Connect Secure < 9.1R9 admin web interface could allow an authenticated attacker to perform an arbitrary code execution using uncontrolled gzip extraction.
- Affected
- Ivanti Pulse Connect Secure
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- ivanti
- Products
- connect secure
- Weakness
- CWE-434
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H