PT-2020-20064 · Pulse · Pulse Connect Secure

Jean-Frédéric Gauron

+5

·

Published

2020-09-29

·

Updated

2024-02-27

·

CVE-2020-8256

CVSS v3.1

4.9

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Pulse Connect Secure versions prior to 9.1R8.2
Description A vulnerability in the Pulse Connect Secure admin web interface could allow an authenticated attacker to gain arbitrary file reading access through Pulse Collaboration via XML External Entity (XXE) vulnerability.
Recommendations For versions prior to 9.1R8.2, update to version 9.1R8.2 or later to resolve the issue.

Exploit

Fix

XXE

Weakness Enumeration

Related Identifiers

CVE-2020-8256

Affected Products

Pulse Connect Secure