CISA Known Exploited Vulnerability

CVE-2020-8243

Ivanti · Pulse Connect Secure

Ivanti Pulse Connect Secure Code Execution Vulnerability

Date added
BOD 22-01 due date
CWE CWE-94
Ransomware Unknown

CISA description

Ivanti Pulse Connect Secure contains an unspecified vulnerability in the admin web interface that could allow an authenticated attacker to upload a custom template to perform code execution.

Required action

Apply updates per vendor instructions.

Notes & references