← Vulnerability feed

Vulnerability record · CVE-2020-11581 · published 6 April 2020

CVE-2020-11581: Pulsesecure pulse connect secure os command injection vulnerability

Pulsesecure · Pulse Connect Secure

An issue was discovered in Pulse Secure Pulse Connect Secure (PCS) through 2020-04-06. The applet in tncc.jar, executed on macOS, Linux, and Solaris clients when a Host Checker policy is enforced, allows a man-in-the-middle attacker to perform OS command injection attacks (against a client) via shell metacharacters to the doCustomRemediateInstructions method, because Runtime.getRuntime().exec() is used.

8.1 CVSS 3.1 High EPSS 9.8% · top 4.6% CWE-78 · OS command injection
8.1CVSS 3.1 base score, v2 9.3
9.8%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

An issue was discovered in Pulse Secure Pulse Connect Secure (PCS) through 2020-04-06. The applet in tncc.jar, executed on macOS, Linux, and Solaris clients when a Host Checker policy is enforced, allows a man-in-the-middle attacker to perform OS command injection attacks (against a client) via shell metacharacters to the doCustomRemediateInstructions method, because Runtime.getRuntime().exec() is used.

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-11581 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.2CVE-2021-22900Pulse Connect Secure admin file upload leads to code injectionPulse Connect Secure before 9.1R11.4 allows an authenticated administrator to upload a maliciously crafted archive through the administrator web inte…KEVEPSS 14%analysed7.2CVE-2020-8218Pulse Connect Secure admin web interface code injectionPulse Connect Secure before 9.1R8 contains a code injection flaw (CWE-94) in the admin web interface. An attacker able to craft a malicious URI can a…KEVEPSS 32%analysed7.2CVE-2019-11539Pulse Secure Connect Secure and Policy Secure admin interface OS command injectionThe admin web interface of Pulse Secure Connect Secure and Policy Secure fails to neutralize input, allowing an authenticated attacker to inject and …KEVEPSS 99%analysed10.0CVE-2016-4787Ivanti connect secure vulnerabilityPulse Connect Secure (PCS) 8.2 before 8.2r1, 8.1 before 8.1r2, 8.0 before 8.0r10, and 7.4 before 7.4r13.4 allow remote attackers to read sensitive sy…EPSS 2.5%9.8CVE-2018-20810Ivanti connect secure inadequate encryption strength vulnerabilitySession data between cluster nodes during cluster synchronization is not properly encrypted in Pulse Secure Pulse Connect Secure (PCS) 8.3RX before 8…EPSS 1.8%9.8CVE-2019-11540Ivanti connect secure vulnerabilityIn Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4 and 8.3RX before 8.3R7.1 and Pulse Policy Secure version 9.0RX before 9.0R3.2 and 5…EPSS 8.3%9.8CVE-2018-6320Ivanti connect secure improper input validation vulnerabilityA vulnerability has been discovered in login.cgi in Pulse Secure Pulse Connect Secure (PCS) 8.1RX before 8.1R12 and 8.3RX before 8.3R2 and Pulse Poli…EPSS 4.1%9.8CVE-2018-5299Pulsesecure pulse connect secure out-of-bounds write vulnerabilityA stack-based Buffer Overflow Vulnerability exists in the web server in Pulse Secure Pulse Connect Secure (PCS) before 8.3R4 and Pulse Policy Secure …EPSS 3.1%

Source: NIST National Vulnerability Database (record CVE-2020-11581), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.