PT-2020-6456 · Pulse · Pulse Connect Secure

Published

2020-09-29

·

Updated

2024-02-27

·

CVE-2020-8243

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Pulse Connect Secure versions prior to 9.1R8.2
Description The issue is related to the Pulse Connect Secure admin web interface, where an authenticated attacker could potentially upload a custom template to execute arbitrary code. This is due to incorrect code generation management in the web interface. An attacker, acting remotely, could exploit this to execute arbitrary code.
Recommendations For versions prior to 9.1R8.2, update to version 9.1R8.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the admin web interface to minimize the risk of exploitation. Avoid using the template upload feature in the affected admin web interface until the issue is resolved.

Fix

Code Injection

Weakness Enumeration

Related Identifiers

BDU:2021-05085
CVE-2020-8243

Affected Products

Pulse Connect Secure