LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2020-8218: Pulse Connect Secure Code Injection Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 7, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Sep 7, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2020-8218 to its Known Exploited Vulnerabilities catalog on Mar 7, 2022, with a federal patch deadline of Sep 7, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

A code injection vulnerability exists in Pulse Connect Secure that allows an attacker to crafted a URI to perform an arbitrary code execution via the admin web interface.

CVE-2020-8218 is a code injection vulnerability in Pulse Secure Pulse Connect Secure. An attacker who can reach the admin web interface may craft a URI that leads to arbitrary code execution on the appliance. This matters because Pulse Connect Secure is commonly used as a remote-access VPN gateway; compromise of the admin interface can give an attacker control over a critical network edge device and a path into internal systems.

Public detail is limited to the CISA description and the CWE classification. Confirm exact affected builds, fixed versions, and any additional conditions against the vendor advisory before acting.

How it works

The weakness is CWE-94 (Improper Control of Generation of Code, or “code injection”). In this class of flaw, untrusted input is incorporated into code or commands that the application later executes. According to the CISA summary, an attacker crafts a URI aimed at the Pulse Connect Secure admin web interface; successful abuse results in arbitrary code execution in the context of the appliance.

No further exploit mechanics, preconditions, or payload details are provided in the given facts. Defenders should treat any unauthenticated or weakly authenticated access to the admin interface as high risk for this class of issue and verify the precise attack surface in the vendor advisory.

Am I affected? How to find it in your systems

Pulse Connect Secure appliances typically sit at the network perimeter as SSL VPN / remote-access gateways and may also host admin portals reachable from management networks or, in misconfigured cases, from the internet.

How to remediate

Patch first. Apply the updates published by the vendor for Pulse Connect Secure exactly as directed in the official advisory for CVE-2020-8218. CISA’s required action is to apply updates per vendor instructions.

If you can't patch immediately

Until the vendor update can be applied, reduce exposure with compensating controls:

If your data may have been exposed

Actively exploited vulnerabilities on perimeter devices can lead to network intrusion and data theft, although ransomware use is not documented for this CVE in the given facts. If you have reason to believe an appliance was compromised, follow your incident-response plan: isolate affected systems, preserve logs, rotate credentials and certificates that may have been exposed, and assess downstream access. You can also run a free exposure scan of your email addresses against known breach data sets to see whether associated accounts appear in prior breaches while you complete containment and recovery.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedPulse Secure · Pulse Connect Secure
WeaknessCWE-94
Added to CISA KEVMar 7, 2022
Federal patch deadlineSep 7, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities