CVE-2020-8254: Path Traversal
A vulnerability in the Pulse Secure Desktop Client < 9.1R9 has Remote Code Execution (RCE) if users can be convinced to connect to a malicious server. This vulnerability only affects Windows PDC.To improve the security of connections between Pulse clients and Pulse Connect Secure, see below recommendation(s):Disable Dynamic certificate trust for PDC.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this Pulse Secure Desktop Client vulnerability?
The vulnerability ID for this Pulse Secure Desktop Client vulnerability is CVE-2020-8254.
What is the severity of CVE-2020-8254?
The severity of CVE-2020-8254 is high.
How does CVE-2020-8254 affect Pulse Secure Desktop Client?
CVE-2020-8254 affects Pulse Secure Desktop Client versions < 9.1R9 on Windows operating system.
What is the risk of CVE-2020-8254?
CVE-2020-8254 has a risk of remote code execution (RCE) if users can be convinced to connect to a malicious server.
Where can I find more information about CVE-2020-8254?
You can find more information about CVE-2020-8254 at the following link: [https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44601](https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44601)