CVE-2020-8260
Last modified
CVE-2020-8260 is a high-severity vulnerability rated 7.2/10 on the CVSS scale. A vulnerability in the Pulse Connect Secure < 9.1R9 admin web interface could allow an authenticated attacker to perform an arbitrary code execution using uncontrolled gzip extraction.. CISA has confirmed active exploitation in the wild. EPSS estimates a 96.48% chance of exploitation in the next 30 days.
Description
A vulnerability in the Pulse Connect Secure < 9.1R9 admin web interface could allow an authenticated attacker to perform an arbitrary code execution using uncontrolled gzip extraction.
Metrics
Exploitation Status
This vulnerability is listed in CISA’s Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Federal agencies must remediate by .
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ivanti | Connect Secure | <= 9.0 |
| Ivanti | Connect Secure | 9.1 |
References
- https://packetstormsecurity.com/files/160619/Pulse-Secure-VPN-Remote-Code-Execution.htmlExploit, Third Party Advisory, VDB Entry
- https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44601Broken Link, Vendor Advisory
- https://packetstormsecurity.com/files/160619/Pulse-Secure-VPN-Remote-Code-Execution.htmlExploit, Third Party Advisory, VDB Entry
- https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44601Broken Link, Vendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-8260US Government Resource
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2020-8260?
How severe is CVE-2020-8260?
How do I fix CVE-2020-8260?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-8254A vulnerability in the Pulse Secure Desktop Client < 9.1R9 h…8.8
- CVE-2020-8255A vulnerability in the Pulse Connect Secure < 9.1R9 admin we…4.9
- CVE-2020-8256A vulnerability in the Pulse Connect Secure < 9.1R8.2 admin …4.9
- CVE-2020-8257Improper privilege management on services run by Citrix Gate…9.8
- CVE-2020-8258Improper privilege management on services run by Citrix Gate…7.5
- CVE-2020-8259Insufficient protection of the server-side encryption keys i…8.1
- CVE-2020-8261A vulnerability in the Pulse Connect Secure / Pulse Policy S…4.3
- CVE-2020-8262A vulnerability in the Pulse Connect Secure / Pulse Policy S…6.1
- CVE-2020-8263A vulnerability in the authenticated user web interface of P…5.4
- CVE-2020-8264In actionpack gem >= 6.0.0, a possible XSS vulnerability exi…6.1
- CVE-2020-8265Node.js versions before 10.23.1, 12.20.1, 14.15.4, 15.5.1 ar…8.1
- CVE-2020-8267A security issue was found in UniFi Protect controller v1.14…5.3
Are you affected by CVE-2020-8260?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
