CVE-2020-8220: Command Injection
A denial of service vulnerability exists in Pulse Connect Secure <9.1R8 that allows an authenticated attacker to perform command injection via the administrator web which can cause DOS.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-8220?
CVE-2020-8220 is a denial of service vulnerability in Pulse Connect Secure <9.1R8 that allows an authenticated attacker to perform command injection via the administrator web which can cause DOS.
How severe is CVE-2020-8220?
CVE-2020-8220 has a severity value of 6.5, which is considered medium.
Which software versions are affected by CVE-2020-8220?
Pulse Connect Secure versions up to 9.1R8 and Pulse Policy Secure versions up to 9.1R7 are affected by CVE-2020-8220.
How can an attacker exploit CVE-2020-8220?
An authenticated attacker can exploit CVE-2020-8220 by performing command injection via the administrator web.
Where can I find more information about CVE-2020-8220?
You can find more information about CVE-2020-8220 in the following link: [Pulse Security Advisories - SA44516](https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44516)