LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2020-8260: Ivanti Pulse Connect Secure Code Execution Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 3, 2021
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
May 3, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2020-8260 to its Known Exploited Vulnerabilities catalog on Nov 3, 2021, with a federal patch deadline of May 3, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Pulse Connect Secure contains an unspecified vulnerability that allows an authenticated attacker to perform code execution using uncontrolled gzip extraction.

CVE-2020-8260: Ivanti Pulse Connect Secure code execution

CVE-2020-8260 is a code-execution vulnerability in Ivanti Pulse Connect Secure. An authenticated attacker can abuse uncontrolled gzip extraction to run code on the appliance. Pulse Connect Secure is commonly used as a remote-access VPN gateway, so successful abuse can put an attacker inside the network perimeter with the privileges of the compromised service.

Public detail on exact mechanics is limited; treat the CISA description and the vendor advisory as the authoritative sources and confirm all version and configuration specifics there before acting.

How it works

The weakness is classified as CWE-434 (unrestricted upload of a file with dangerous type). In this case the attack surface is uncontrolled gzip extraction: after authentication, an attacker can supply a crafted archive that the product extracts without adequate path or content controls. That extraction step can be leveraged to place or overwrite files in locations that lead to code execution on the appliance.

Because the attacker must already be authenticated, the vulnerability is not a pure unauthenticated remote code execution flaw. However, once a valid session or credential is obtained—through phishing, credential stuffing, or other means—the extraction path becomes a route to full control of the VPN concentrator. Exact payload construction and file-system layout details are not provided in the public summary; do not assume exploit specifics beyond what the vendor advisory documents.

Am I affected? How to find it in your systems

Pulse Connect Secure appliances typically sit at the network edge as SSL VPN gateways, often reachable from the internet on HTTPS and sometimes on dedicated management interfaces. Inventory every instance by:

Because the flaw requires authentication, also examine authentication and administrative logs for unusual successful logins, unexpected admin-session creation, or gzip/archive upload activity around the time of any suspected incident. Telemetry that shows sudden process spawning, unexpected file writes under the appliance’s web or temporary directories, or outbound connections originating from the VPN host after an authenticated session should be treated as suspicious and investigated. Confirm exact log signatures and version ranges with the vendor advisory; do not rely on third-party version lists alone.

How to remediate

Patch first. Apply the updates published by Ivanti for Pulse Connect Secure exactly as described in the vendor advisory for CVE-2020-8260. CISA’s required action is to apply updates per vendor instructions; follow that guidance and verify the installed build after the upgrade.

After patching, harden the appliance for this class of weakness:

If you can't patch immediately

Until the vendor update can be applied, reduce exposure with compensating controls:

These steps only buy time; they do not replace the vendor patch.

If your data may have been exposed

Actively exploited VPN vulnerabilities frequently lead to network breaches and data theft even when ransomware use has not been documented for the specific CVE. If you have reason to believe an appliance was compromised, treat connected identity stores, session logs, and any data accessible through the VPN as potentially exposed: isolate the host, preserve forensic images, rotate credentials, and begin incident-response scoping. As a quick additional check, you can run a free exposure scan of your email addresses against known breach data sets to see whether credentials tied to your domain have already appeared in public dumps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedIvanti · Pulse Connect Secure
WeaknessCWE-434
Added to CISA KEVNov 3, 2021
Federal patch deadlineMay 3, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities