CVE-2020-8956: Low severity pulse secure desktop vulnerability
Pulse Secure Desktop Client 9.0Rx before 9.0R5 and 9.1Rx before 9.1R4 on Windows reveals users' passwords if Save Settings is enabled.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-8956?
The severity of CVE-2020-8956 is low.
What is affected by CVE-2020-8956?
Pulse Secure Desktop Client versions 9.0Rx before 9.0R5 and 9.1Rx before 9.1R4 on Windows are affected by CVE-2020-8956.
How does CVE-2020-8956 expose users' passwords?
CVE-2020-8956 exposes users' passwords if the Save Settings feature is enabled in Pulse Secure Desktop Client versions 9.0Rx before 9.0R5 and 9.1Rx before 9.1R4 on Windows.
How can I fix CVE-2020-8956?
To fix CVE-2020-8956, users should update Pulse Secure Desktop Client to version 9.0R5 or 9.1R4 or higher on Windows and disable the Save Settings feature.
Where can I find more information about CVE-2020-8956?
More information about CVE-2020-8956 can be found in the Pulse Secure KB article: https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44601