CISA Known Exploited Vulnerability

CVE-2020-8260

Ivanti · Pulse Connect Secure

Ivanti Pulse Connect Secure Code Execution Vulnerability

Date added
BOD 22-01 due date
CWE CWE-434
Ransomware Unknown

CISA description

Pulse Connect Secure contains an unspecified vulnerability that allows an authenticated attacker to perform code execution using uncontrolled gzip extraction.

Required action

Apply updates per vendor instructions.

Notes & references