ZeroHour

CVE-2020-8260

KEV PoC mass

Authenticated RCE in Ivanti Pulse Connect Secure admin web interface (pre-9.1R9)

CISA: Ivanti Pulse Connect Secure Code Execution Vulnerability

CVSS 3.1
7.2 high
EPSS
96%p100
Published
()
KEV added
AI analysis

Ivanti Pulse Connect Secure versions before 9.1R9 contain a vulnerability (mapped to CWE-434) in the administrative web interface in which compressed uploads are handled with uncontrolled gzip extraction. An authenticated attacker with high-privilege (admin-level) access to that interface can send a crafted gzip-compressed file, triggering arbitrary code execution on the appliance with high impact to confidentiality, integrity, and availability (CVSS 3.1: 7.2, AV:N/PR:H). Successful exploitation yields arbitrary code execution on the VPN appliance itself, effectively enabling full compromise of the gateway that terminates the organization's VPN sessions. Any organization running Pulse Connect Secure on a release prior to 9.1R9 is affected, making the typical target an enterprise or government SSL VPN appliance accessible to anyone holding admin credentials. Exploitation is in the wild: the flaw is in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03), carries a 96.5% EPSS exploitation probability (100th percentile), and a public proof of concept is available.

What to do: Upgrade Pulse Connect Secure to 9.1R9 or later per the vendor's instructions; given the related patch-bypass flaw CVE-2021-22937 and the 'new urgent update' headlines, ensure the most recent available 9.1R release is applied rather than relying solely on the original 9.1R9 fix. Restrict the admin web interface to trusted management networks and review administrative accounts. Because the flaw is on CISA's KEV list and CISA has published malware analysis reports for Pulse Secure-targeted samples, hunt patched and unpatched devices for signs of compromise (e.g., web shells or implants).

Affected
ivanti connect secureall releases prior to 9.1R9 (< 9.1R9)
Estimated exposure
mass≈10^5 devices: a six-figure installed base of Pulse Connect Secure appliances, with tens of thousands internet-exposed in public scans at the time of the 2021… — Pulse Connect Secure was one of the most widely deployed enterprise SSL VPN appliances (heavy Fortune 500 and government adoption), and public internet scans during the 2021 Pulse Secure campaign repeatedly showed on the order of 10^4–10^5…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability in the Pulse Connect Secure < 9.1R9 admin web interface could allow an authenticated attacker to perform an arbitrary code execution using uncontrolled gzip extraction.

CISA Known Exploited Vulnerability
Affected
Ivanti Pulse Connect Secure
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
ivanti
Products
connect secure
Weakness
CWE-434
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news