CVE-2020-15352
Last modified
CVE-2020-15352 is a high-severity vulnerability rated 7.2/10 on the CVSS scale. An XML external entity (XXE) vulnerability in Pulse Connect Secure (PCS) before 9.1R9 and Pulse Policy Secure (PPS) before 9.1R9 allows remote authenticated admins to conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML request.. EPSS estimates a 3.16% chance of exploitation in the next 30 days.
Description
An XML external entity (XXE) vulnerability in Pulse Connect Secure (PCS) before 9.1R9 and Pulse Policy Secure (PPS) before 9.1R9 allows remote authenticated admins to conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML request.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Ivanti | Connect Secure | 9.1 | — |
| Pulsesecure | Pulse Connect Secure | <= 9.0 | — |
| Ivanti | Policy Secure | 9.1 | R1 |
| Pulsesecure | Pulse Policy Secure | <= 9.0 | — |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-15352?
How severe is CVE-2020-15352?
How do I fix CVE-2020-15352?
Are you affected by CVE-2020-15352?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
