CVE-2020-8243: Ivanti Pulse Connect Secure Code Execution Vulnerability
Ivanti Pulse Connect Secure contains an unspecified vulnerability in the admin web interface that could allow an authenticated attacker to upload a custom template to perform code execution.
Other sources
A vulnerability in the Pulse Connect Secure < 9.1R8.2 admin web interface could allow an authenticated attacker to upload custom template to perform an arbitrary code execution.
— NVD
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-8243?
CVE-2020-8243 is the identifier for the Ivanti Pulse Connect Secure Code Execution Vulnerability.
What is the severity of CVE-2020-8243?
CVE-2020-8243 has a severity level of high (7.2).
Which software is affected by CVE-2020-8243?
Ivanti Pulse Connect Secure versions up to 9.1-r8.1 and Pulse Policy Secure versions up to 9.1-r8.1 are affected by CVE-2020-8243.
How can an attacker exploit CVE-2020-8243?
An authenticated attacker can exploit CVE-2020-8243 by uploading a custom template via the admin web interface, which allows for code execution.
How can I fix the vulnerability identified in CVE-2020-8243?
To fix CVE-2020-8243, update Ivanti Pulse Connect Secure and Pulse Policy Secure to version 9.1-r8.2 or later.