
Cloud Vulnerability DB
A community-led vulnerabilities database
A vulnerability (CVE-2020-8260) was discovered in the Pulse Connect Secure admin web interface affecting versions prior to 9.1R9. The vulnerability, disclosed on October 28, 2020, allows an authenticated attacker with administrative access to perform arbitrary code execution using uncontrolled gzip extraction (NVD, AttackerKB).
The vulnerability has a CVSS v3.1 base score of 7.2 (High) with the following metrics: Attack Vector: Network, Attack Complexity: Low, Privileges Required: High, User Interaction: None, Scope: Unchanged, and Impact scores of High for Confidentiality, Integrity, and Availability. The flaw exists in the way archive files (.TAR) are extracted in the administrator web interface (AttackerKB).
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code with root privileges on the affected system. The attacker could potentially remount the filesystem, create persistent backdoors, extract and decrypt credentials, compromise VPN clients, or pivot into the internal network (Hacker News).
The vulnerability requires authentication and high privileges for exploitation. It has been confirmed to be exploited in the wild, particularly in attacks targeting defense, government, and financial entities in the U.S. and beyond. The exploitation was used to circumvent multi-factor authentication protections and breach enterprise networks (Hacker News).
The vulnerability was initially patched in Pulse Connect Secure version 9.1R9 released in October 2020. However, due to an incomplete fix, users are strongly recommended to upgrade to Pulse Connect Secure (PCS) version 9.1R12 or later for complete protection (Hacker News).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."