A vulnerability in the Pulse Connect Secure < 9.1R8.2 admin web interface could allow an authenticated attacker to upload custom template to perform an arbitrary code execution.
History

Wed, 12 Feb 2025 20:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:pulsesecure:pulse_connect_secure:*:*:*:*:*:*:*:*
cpe:2.3:a:pulsesecure:pulse_policy_secure:*:*:*:*:*:*:*:*
cpe:2.3:a:ivanti:connect_secure:*:*:*:*:*:*:*:*
cpe:2.3:a:ivanti:policy_secure:*:*:*:*:*:*:*:*
Vendors & Products Pulsesecure
Pulsesecure pulse Connect Secure
Pulsesecure pulse Policy Secure

Tue, 04 Feb 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics kev

{'dateAdded': '2021-11-03'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'active', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published:

Updated: 2025-02-04T18:20:32.768Z

Reserved: 2020-01-28T00:00:00.000Z

Link: CVE-2020-8243

cve-icon Vulnrichment

Updated: 2024-08-04T09:56:27.945Z

cve-icon NVD

Status : Analyzed

Published: 2020-09-30T18:15:29.070

Modified: 2025-02-12T19:56:52.180

Link: CVE-2020-8243

cve-icon Redhat

No data.