CISA Known Exploited Vulnerability

CVE-2020-8218

Pulse Secure · Pulse Connect Secure

Pulse Connect Secure Code Injection Vulnerability

Date added
BOD 22-01 due date
CWE CWE-94
Ransomware Unknown

CISA description

A code injection vulnerability exists in Pulse Connect Secure that allows an attacker to crafted a URI to perform an arbitrary code execution via the admin web interface.

Required action

Apply updates per vendor instructions.