LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2020-8243: Ivanti Pulse Connect Secure Code Execution Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 3, 2021
CVSS 7.2 · High⚠ Actively exploited (CISA KEV)
7.2
CVSS score
High
Severity
Active
CISA KEV
No
Ransomware use
May 3, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2020-8243 to its Known Exploited Vulnerabilities catalog on Nov 3, 2021, with a federal patch deadline of May 3, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

A vulnerability in the Pulse Connect Secure < 9.1R8.2 admin web interface could allow an authenticated attacker to upload custom template to perform an arbitrary code execution.

CVE-2020-8243 is a code-execution vulnerability in Ivanti Pulse Connect Secure affecting the admin web interface. An authenticated attacker who can reach that interface may upload a custom template and achieve code execution on the appliance. Because Pulse Connect Secure is commonly used as a remote-access VPN gateway, successful abuse can give an attacker a foothold inside the network perimeter. Public detail beyond the CISA description is limited; confirm exact scope and fixed releases against the vendor advisory.

How it works

The weakness is classified as CWE-94 (code injection). In this case the admin web interface accepts a custom template upload. When that template is processed without adequate validation or sandboxing, the attacker’s content can be interpreted as executable code on the device. The attack requires prior authentication to the administrative interface; it is not described as unauthenticated remote code execution. Exact upload paths, template formats, or payload mechanics are not specified in the available summary, so defenders should treat any authenticated admin-template functionality as the attack surface and verify details in the vendor advisory.

Am I affected? How to find it in your systems

Ivanti Pulse Connect Secure appliances typically sit at the network edge as SSL VPN or remote-access gateways, often reachable from the internet on HTTPS and managed through a dedicated admin web UI. Inventory steps:

Telemetry signs of exploitation are not detailed in the public summary. Review admin-interface access logs, template-upload or file-management events, unexpected process creation, and configuration changes. Correlate with authentication logs for unusual admin accounts or source IPs. Any anomalous template activity should be treated as suspicious until proven otherwise.

How to remediate

Patch first. Apply the updates published by Ivanti for Pulse Connect Secure exactly as described in the vendor advisory and in accordance with CISA’s required action (“Apply updates per vendor instructions”). After patching:

If you can't patch immediately

Until the vendor update can be installed, reduce exposure with compensating controls:

These measures lower risk but do not replace the patch.

If your data may have been exposed

Actively exploited vulnerabilities on internet-facing VPN appliances can lead to network intrusion and data theft. If you have reason to believe this CVE was used against your environment, follow your incident-response plan: isolate affected systems, preserve logs, rotate credentials, and assess lateral movement. You can also run a free exposure scan of your email addresses against known breach data sets to check whether associated credentials or personal information have already appeared in public breach corpora.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedIvanti · Pulse Connect Secure
WeaknessCWE-94
CVSS base score7.2 (High)
CVSS vectorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
PublishedSep 30, 2020
Added to CISA KEVNov 3, 2021
Federal patch deadlineMay 3, 2022
Known ransomware useNot documented
Check if your data is exposed →

References

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities