CVE-2020-8256: XEE
A vulnerability in the Pulse Connect Secure < 9.1R8.2 admin web interface could allow an authenticated attacker to gain arbitrary file reading access through Pulse Collaboration via XML External Entity (XXE) vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-8256?
CVE-2020-8256 is a vulnerability in the Pulse Connect Secure < 9.1R8.2 admin web interface that could allow an authenticated attacker to gain arbitrary file reading access through Pulse Collaboration via XML External Entity (XXE) vulnerability.
How can an attacker exploit CVE-2020-8256?
An authenticated attacker can exploit CVE-2020-8256 by utilizing Pulse Collaboration to gain unauthorized file reading access through XXE injection.
What is the severity of CVE-2020-8256?
CVE-2020-8256 has a severity rating of 4.9 (medium).
Which software versions are affected by CVE-2020-8256?
Pulse Connect Secure versions < 9.1R8.2, including 9.0 and 9.1, are affected by CVE-2020-8256.
How can I mitigate CVE-2020-8256?
To mitigate CVE-2020-8256, it is recommended to upgrade Pulse Connect Secure to version 9.1R8.2 or higher.