Vulnerability record · CVE-2020-8218 · published 30 July 2020
CVE-2020-8218: Pulse Connect Secure admin web interface code injection
Ivanti · Connect Secure
Pulse Connect Secure before 9.1R8 contains a code injection flaw (CWE-94) in the admin web interface. An attacker able to craft a malicious URI can achieve arbitrary code execution on the appliance. Because the affected product is a remote-access VPN gateway, compromise can expose the internal network it protects.
Description
A code injection vulnerability exists in Pulse Connect Secure <9.1R8 that allows an attacker to crafted a URI to perform an arbitrary code execution via the admin web interface.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityIt is a KEV-listed, publicly exploited code injection flaw with high EPSS, but exploitation requires high (admin) privileges, which limits the population of viable attackers.
What it is
Pulse Connect Secure before 9.1R8 contains a code injection flaw (CWE-94) in the admin web interface. An attacker able to craft a malicious URI can achieve arbitrary code execution on the appliance. Because the affected product is a remote-access VPN gateway, compromise can expose the internal network it protects.
Impact
An attacker gains arbitrary code execution on the Pulse Connect Secure appliance, with high impact to confidentiality, integrity and availability per the CVSS vector. On a VPN gateway this can enable credential theft, session hijacking and lateral movement into protected networks.
Attack surface
Reached over the network via a crafted URI against the admin web interface, per the CVSS vector AV:N/AC:L/PR:H/UI:N. The PR:H rating means the attacker needs high privileges, i.e. administrative access to the interface, and no user interaction is required.
Exploitation
Listed in CISA KEV since 2022-03-07 with a required action to apply vendor updates, and EPSS shows a 30-day probability of 0.32739 (98.3rd percentile). A public third-party advisory is tagged Exploit, indicating exploit code or detail is publicly available; no ransomware campaign use is documented.
What to do
- Upgrade Pulse Connect Secure to 9.1R8 or later per vendor advisory SA44516.
- Restrict network access to the admin web interface to trusted management networks and disable it from untrusted zones.
- Enforce strong, unique administrative credentials and MFA, and rotate admin credentials after any suspected exposure.
- Monitor vendor advisories and KEV for follow-up fixes, since this appliance family has a history of exploited flaws.
Detection
- Review web and appliance logs for anomalous or malformed URIs targeting admin interface endpoints.
- Alert on unexpected processes, files or outbound connections originating from the Pulse Connect Secure appliance.
- Audit admin interface authentication events for logins from unusual source IPs or at unusual times.
- Hunt for indicators published in the GoSecure advisory and any vendor IOC guidance.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2020-8218 to the Known Exploited Vulnerabilities catalog on 7 March 2022 as "Pulse Connect Secure Code Injection Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 7 September 2022.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44516 | Vendor Advisory |
| https://www.gosecure.net/blog/2020/11/13/forget-your-perimeter-part-2-four-vulnerabilities-in-pulse-connect-secure/ | ExploitThird Party Advisory |
| https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44516 | Vendor Advisory |
| https://www.gosecure.net/blog/2020/11/13/forget-your-perimeter-part-2-four-vulnerabilities-in-pulse-connect-secure/ | ExploitThird Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-8218 | US Government Resource |
Track CVE-2020-8218 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-8218), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.