Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2020-8260
Ivanti Connect Secure vulnerability analysis and mitigation

Overview

A vulnerability (CVE-2020-8260) was discovered in the Pulse Connect Secure admin web interface affecting versions prior to 9.1R9. The vulnerability, disclosed on October 28, 2020, allows an authenticated attacker with administrative access to perform arbitrary code execution using uncontrolled gzip extraction (NVD, AttackerKB).

Technical details

The vulnerability has a CVSS v3.1 base score of 7.2 (High) with the following metrics: Attack Vector: Network, Attack Complexity: Low, Privileges Required: High, User Interaction: None, Scope: Unchanged, and Impact scores of High for Confidentiality, Integrity, and Availability. The flaw exists in the way archive files (.TAR) are extracted in the administrator web interface (AttackerKB).

Impact

Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code with root privileges on the affected system. The attacker could potentially remount the filesystem, create persistent backdoors, extract and decrypt credentials, compromise VPN clients, or pivot into the internal network (Hacker News).

Exploitability

The vulnerability requires authentication and high privileges for exploitation. It has been confirmed to be exploited in the wild, particularly in attacks targeting defense, government, and financial entities in the U.S. and beyond. The exploitation was used to circumvent multi-factor authentication protections and breach enterprise networks (Hacker News).

Mitigation and workarounds

The vulnerability was initially patched in Pulse Connect Secure version 9.1R9 released in October 2020. However, due to an incomplete fix, users are strongly recommended to upgrade to Pulse Connect Secure (PCS) version 9.1R12 or later for complete protection (Hacker News).

Additional resources


SourceThis report was generated using AI

Related Ivanti Connect Secure vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-55147HIGH8.8
  • Ivanti Connect Secure logoIvanti Connect Secure
  • cpe:2.3:a:ivanti:connect_secure
NoYesSep 09, 2025
CVE-2025-55148HIGH7.6
  • Ivanti Connect Secure logoIvanti Connect Secure
  • cpe:2.3:a:ivanti:connect_secure
NoYesSep 09, 2025
CVE-2025-8712MEDIUM5.4
  • Ivanti Connect Secure logoIvanti Connect Secure
  • cpe:2.3:a:ivanti:policy_secure
NoYesSep 09, 2025
CVE-2025-8711MEDIUM5.4
  • Ivanti Connect Secure logoIvanti Connect Secure
  • cpe:2.3:a:ivanti:connect_secure
NoYesSep 09, 2025
CVE-2025-55146MEDIUM4.9
  • Ivanti Connect Secure logoIvanti Connect Secure
  • cpe:2.3:a:ivanti:connect_secure
NoYesSep 09, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management