CVE-2020-8261: Medium severity ivanti pulse connect secure vulnerability
Published Oct 28, 2020
·Updated
A vulnerability in the Pulse Connect Secure / Pulse Policy Secure < 9.1R9 is vulnerable to arbitrary cookie injection.
Affected Software
34 affected components
PulseSecure Pulse Connect Secure<9.1
PulseSecure Pulse Connect Secure=9.1-r1
PulseSecure Pulse Connect Secure=9.1-r2
PulseSecure Pulse Connect Secure=9.1-r3
PulseSecure Pulse Connect Secure=9.1-r4
PulseSecure Pulse Connect Secure=9.1-r5
PulseSecure Pulse Connect Secure=9.1-r6
PulseSecure Pulse Connect Secure=9.1-r7
PulseSecure Pulse Connect Secure=9.1-r8
PulseSecure Pulse Policy Secure<9.1
PulseSecure Pulse Policy Secure=9.1-r1
PulseSecure Pulse Policy Secure=9.1-r2
PulseSecure Pulse Policy Secure=9.1-r3
PulseSecure Pulse Policy Secure=9.1-r4
PulseSecure Pulse Policy Secure=9.1-r5
PulseSecure Pulse Policy Secure=9.1-r6
PulseSecure Pulse Policy Secure=9.1-r7
PulseSecure Pulse Policy Secure=9.1-r8
Ivanti Connect Secure=9.1-r1
Ivanti Connect Secure=9.1-r2
Ivanti Connect Secure=9.1-r3
Ivanti Connect Secure=9.1-r4
Ivanti Connect Secure=9.1-r5
Ivanti Connect Secure=9.1-r6
Ivanti Connect Secure=9.1-r7
Ivanti Connect Secure=9.1-r8
Ivanti Policy Secure=9.1-r1
Ivanti Policy Secure=9.1-r2
Ivanti Policy Secure=9.1-r3
Ivanti Policy Secure=9.1-r4
Ivanti Policy Secure=9.1-r5
Ivanti Policy Secure=9.1-r6
Ivanti Policy Secure=9.1-r7
Ivanti Policy Secure=9.1-r8
Event History
Oct 28, 2020
CVE Published
via MITRE·12:47 PM
Data Sourced
via MITRE·12:47 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2020-8261.
2
What is the affected software?
The affected software is Pulse Connect Secure / Pulse Policy Secure versions < 9.1R9.
3
Is this vulnerability easy to exploit?
The severity level of this vulnerability is medium (CVSS score of 4.3), indicating it may not be easy to exploit.
4
What is the potential impact of this vulnerability?
This vulnerability allows for arbitrary cookie injection, which can lead to authentication bypass or session hijacking.
5
How can I fix this vulnerability?
To fix this vulnerability, it is recommended to update to Pulse Connect Secure / Pulse Policy Secure version 9.1R9 or later.