CVE-2020-8218: Pulse Connect Secure Code Injection Vulnerability
A code injection vulnerability exists in Pulse Connect Secure that allows an attacker to crafted a URI to perform an arbitrary code execution via the admin web interface.
Other sources
A code injection vulnerability exists in Pulse Connect Secure <9.1R8 that allows an attacker to crafted a URI to perform an arbitrary code execution via the admin web interface.
— NVD
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-8218?
CVE-2020-8218 is a code injection vulnerability in Pulse Connect Secure <9.1R8 that allows an attacker to execute arbitrary code.
What is the severity of CVE-2020-8218?
The severity of CVE-2020-8218 is rated as high with a CVSS score of 7.2.
Which software versions are affected by CVE-2020-8218?
Pulse Connect Secure versions up to 9.1R8 are affected by CVE-2020-8218.
How can an attacker exploit CVE-2020-8218?
An attacker can exploit CVE-2020-8218 by crafting a URI to perform an arbitrary code execution via the admin web interface.
Where can I find more information about CVE-2020-8218?
You can find more information about CVE-2020-8218 at the following references: [Pulse Secure Advisory](https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44516) and [GoSecure Blog](https://www.gosecure.net/blog/2020/11/13/forget-your-perimeter-part-2-four-vulnerabilities-in-pulse-connect-secure/).