CVE-2020-8255: Input Validation
A vulnerability in the Pulse Connect Secure < 9.1R9 admin web interface could allow an authenticated attacker to perform an arbitrary file reading vulnerability is fixed using encrypted URL blacklisting that prevents these messages.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-8255?
CVE-2020-8255 is a vulnerability in the Pulse Connect Secure < 9.1R9 admin web interface that could allow an authenticated attacker to perform an arbitrary file reading.
How can an attacker exploit CVE-2020-8255?
An attacker can exploit CVE-2020-8255 by exploiting an arbitrary file reading vulnerability in the Pulse Connect Secure admin web interface.
What is the severity of CVE-2020-8255?
The severity of CVE-2020-8255 is medium with a severity value of 4.9.
What software versions are affected by CVE-2020-8255?
Pulsesecure Pulse Secure Desktop Client version < 9.1R9 is affected by CVE-2020-8255.
How can I fix CVE-2020-8255?
The vulnerability in CVE-2020-8255 can be fixed by applying the encrypted URL blacklisting patch provided by Pulse Secure.