
Cloud Vulnerability DB
A community-led vulnerabilities database
An improper authentication vulnerability (CVE-2020-8206) was discovered in Pulse Connect Secure versions prior to 9.1RB. The vulnerability was disclosed on July 30, 2020, affecting Pulse Connect Secure VPN systems (NVD).
The vulnerability allows an attacker with a user's primary credentials to bypass the Google Time-based One-Time Password (TOTP) authentication mechanism. The vulnerability received a CVSS score of 7.0, indicating moderate severity with network vector access and medium attack complexity (Rapid7).
If successfully exploited, this vulnerability compromises the multi-factor authentication mechanism by allowing attackers to bypass the Google TOTP security layer when they have obtained a user's primary credentials, potentially leading to unauthorized access to the VPN system (Register).
The vulnerability requires the attacker to first obtain a user's primary credentials before they can attempt to bypass the Google TOTP authentication. This prerequisite somewhat limits the ease of exploitation but still presents a significant security risk (NVD).
The vulnerability was addressed in Pulse Connect Secure (PCS) version 9.1R8 and Pulse Policy Secure (PPS) version 9.1R8. Organizations using affected versions are advised to upgrade to these patched versions to mitigate the risk (Register).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."