CVE-2020-11580
Ivanti Connect Secure vulnerability analysis and mitigation

Overview

An issue was discovered in Pulse Secure Pulse Connect Secure (PCS) through 2020-04-06. The applet in tncc.jar, executed on macOS, Linux, and Solaris clients when a Host Checker policy is enforced, accepts an arbitrary SSL certificate. The Host Checker is a client-side component that the Pulse Connect Secure appliance may require for VPN connection, performing basic checks on the client according to server policies (Git LSD).

Technical details

The vulnerability stems from the Host Checker's implementation of a custom protocol for server communication. The client does not validate server certificates or hostnames, likely implemented to support misconfigured instances. This is evidenced in the HttpNAR class where trustAllCerts() and allowHostnameMismatch() functions are executed when initializing the connection to a server. The code implements a TrustManager that accepts all certificates without validation (Git LSD).

Impact

The vulnerability allows attackers in a position to perform a Man-in-the-Middle attack to spoof the server and potentially execute arbitrary commands on the client system. This is particularly concerning as the Host Checker is a required component for VPN connections in many deployments (Git LSD).

Mitigation and workarounds

The vulnerability was addressed in subsequent versions of Pulse Connect Secure. Organizations should ensure they are running a patched version of the software. The fix likely includes proper certificate validation in the Host Checker component (Git LSD).

Additional resources


SourceThis report was generated using AI

Related Ivanti Connect Secure vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-55147HIGH8.8
  • Ivanti Connect SecureIvanti Connect Secure
  • cpe:2.3:a:ivanti:connect_secure
NoYesSep 09, 2025
CVE-2025-55148HIGH7.6
  • Ivanti Connect SecureIvanti Connect Secure
  • cpe:2.3:a:ivanti:policy_secure
NoYesSep 09, 2025
CVE-2025-8712MEDIUM5.4
  • Ivanti Connect SecureIvanti Connect Secure
  • cpe:2.3:a:ivanti:connect_secure
NoYesSep 09, 2025
CVE-2025-8711MEDIUM5.4
  • Ivanti Connect SecureIvanti Connect Secure
  • cpe:2.3:a:ivanti:connect_secure
NoYesSep 09, 2025
CVE-2025-55146MEDIUM4.9
  • Ivanti Connect SecureIvanti Connect Secure
  • cpe:2.3:a:ivanti:connect_secure
NoYesSep 09, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management