CVE-2020-12880: Medium severity ivanti pulse connect secure vulnerability
An issue was discovered in Pulse Policy Secure (PPS) and Pulse Connect Secure (PCS) Virtual Appliance before 9.1R8. By manipulating a certain kernel boot parameter, it can be tricked into dropping into a root shell in a pre-install phase where the entire source code of the appliance is available and can be retrieved. (The source code is otherwise inaccessible because the appliance has its hard disks encrypted, and no root shell is available during normal operation.)
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability identifier for this issue?
The vulnerability identifier for this issue is CVE-2020-12880.
What is the severity of CVE-2020-12880?
The severity of CVE-2020-12880 is medium with a CVSS score of 5.5.
Which software versions are affected by this vulnerability?
Pulse Connect Secure versions up to and including 9.1 and Pulse Policy Secure versions up to and including 9.1 are affected by this vulnerability.
How can the vulnerability be exploited?
This vulnerability can be exploited by manipulating a certain kernel boot parameter to drop into a root shell during the pre-install phase.
Where can I find more information about this vulnerability?
More information about this vulnerability can be found on the Pulse Secure Knowledge Base at the following links: [Link 1](https://kb.pulsesecure.net/?atype=sa), [Link 2](https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44516).