← Vulnerability feed

Vulnerability record · CVE-2020-8218 · published 30 July 2020

CVE-2020-8218: Pulse Connect Secure admin web interface code injection

Ivanti · Connect Secure

Pulse Connect Secure before 9.1R8 contains a code injection flaw (CWE-94) in the admin web interface. An attacker able to craft a malicious URI can achieve arbitrary code execution on the appliance. Because the affected product is a remote-access VPN gateway, compromise can expose the internal network it protects.

7.2 CVSS 3.1 High CISA KEV since 7 Mar 2022 EPSS 32% · top 1.7% CWE-94 · Code injection
7.2CVSS 3.1 base score, v2 6.5
32%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
3Affected product versions listed by NVD
5References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

A code injection vulnerability exists in Pulse Connect Secure <9.1R8 that allows an attacker to crafted a URI to perform an arbitrary code execution via the admin web interface.

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: medium.

high priorityIt is a KEV-listed, publicly exploited code injection flaw with high EPSS, but exploitation requires high (admin) privileges, which limits the population of viable attackers.

What it is

Pulse Connect Secure before 9.1R8 contains a code injection flaw (CWE-94) in the admin web interface. An attacker able to craft a malicious URI can achieve arbitrary code execution on the appliance. Because the affected product is a remote-access VPN gateway, compromise can expose the internal network it protects.

Impact

An attacker gains arbitrary code execution on the Pulse Connect Secure appliance, with high impact to confidentiality, integrity and availability per the CVSS vector. On a VPN gateway this can enable credential theft, session hijacking and lateral movement into protected networks.

Attack surface

Reached over the network via a crafted URI against the admin web interface, per the CVSS vector AV:N/AC:L/PR:H/UI:N. The PR:H rating means the attacker needs high privileges, i.e. administrative access to the interface, and no user interaction is required.

Exploitation

Listed in CISA KEV since 2022-03-07 with a required action to apply vendor updates, and EPSS shows a 30-day probability of 0.32739 (98.3rd percentile). A public third-party advisory is tagged Exploit, indicating exploit code or detail is publicly available; no ransomware campaign use is documented.

What to do

  • Upgrade Pulse Connect Secure to 9.1R8 or later per vendor advisory SA44516.
  • Restrict network access to the admin web interface to trusted management networks and disable it from untrusted zones.
  • Enforce strong, unique administrative credentials and MFA, and rotate admin credentials after any suspected exposure.
  • Monitor vendor advisories and KEV for follow-up fixes, since this appliance family has a history of exploited flaws.

Detection

  • Review web and appliance logs for anomalous or malformed URIs targeting admin interface endpoints.
  • Alert on unexpected processes, files or outbound connections originating from the Pulse Connect Secure appliance.
  • Audit admin interface authentication events for logins from unusual source IPs or at unusual times.
  • Hunt for indicators published in the GoSecure advisory and any vendor IOC guidance.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2020-8218 to the Known Exploited Vulnerabilities catalog on 7 March 2022 as "Pulse Connect Secure Code Injection Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 7 September 2022.

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-8218 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2021-22893Ivanti Pulse Connect Secure authentication bypass and use-after-free enabling RCEPulse Connect Secure 9.0R3/9.1R1 and higher contains an authentication bypass exposed through the Windows File Share Browser and Pulse Secure Collabo…KEVEPSS 47%analysed10.0CVE-2019-11510Pulse Connect Secure path traversal allows unauthenticated file readPulse Connect Secure versions 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4 contain a path traversal (CWE-22) flaw. An unauthentica…KEVEPSS 100%analysed9.8CVE-2025-22457Ivanti Connect Secure, Policy Secure and ZTA Gateways stack buffer overflow RCEA stack-based buffer overflow (CWE-121/CWE-787) in Ivanti Connect Secure, Policy Secure and ZTA Gateways allows a remote, unauthenticated attacker to…KEVEPSS 100%analysed9.1CVE-2024-21887Ivanti Connect Secure and Policy Secure web component command injectionIvanti Connect Secure and Policy Secure (9.x, 22.x) contain a command injection flaw (CWE-77) in web components. An authenticated administrator can s…KEVEPSS 100%analysed9.0CVE-2025-0282Ivanti Connect Secure stack buffer overflow enables unauthenticated RCEA stack-based buffer overflow (CWE-121/CWE-787) in Ivanti Connect Secure, Policy Secure and Neurons for ZTA gateways lets a remote, unauthenticated a…KEVEPSS 100%analysed8.8CVE-2021-22894Pulse Connect Secure buffer overflow allows root code executionPulse Connect Secure before 9.1R11.4 contains a buffer overflow reachable through a maliciously crafted meeting room. A remote authenticated attacker…KEVEPSS 41%analysed8.8CVE-2021-22899Pulse Connect Secure command injection via Windows Resource ProfilesPulse Connect Secure before 9.1R11.4 contains a command injection flaw (CWE-77) in the Windows Resource Profiles feature. An attacker who can authent…KEVEPSS 23%analysed8.2CVE-2024-21893Ivanti Connect Secure SAML SSRF allows unauthenticated resource accessThe SAML component of Ivanti Connect Secure, Policy Secure and Neurons for ZTA contains a server-side request forgery flaw that lets an attacker reac…KEVEPSS 100%analysed

Source: NIST National Vulnerability Database (record CVE-2020-8218), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.