PT-2020-20064 · Pulse · Pulse Connect Secure

Jean-Frédéric Gauron

+5

·

Published

2020-09-29

·

Updated

2024-02-27

·

CVE-2020-8256

CVSS v2.0
4.0
VectorAV:N/AC:L/Au:S/C:P/I:N/A:N

Name of the Vulnerable Software and Affected Versions:

Pulse Connect Secure versions prior to 9.1R8.2

Description:

A vulnerability in the Pulse Connect Secure admin web interface could allow an authenticated attacker to gain arbitrary file reading access through Pulse Collaboration via XML External Entity (XXE) vulnerability.

Recommendations:

For versions prior to 9.1R8.2, update to version 9.1R8.2 or later to resolve the issue.

Exploit

Fix

XXE

Weakness Enumeration

Related Identifiers

CVE-2020-8256

Affected Products

Pulse Connect Secure