Vulnerability record · CVE-2020-8243 · published 30 September 2020
CVE-2020-8243: Pulse Connect Secure admin interface template upload code execution
Ivanti · Connect Secure
Pulse Connect Secure before 9.1R8.2 allows an authenticated attacker to upload a custom template through the admin web interface, resulting in arbitrary code execution. Because the flaw is in the administrative interface and yields code execution on the appliance, it is a serious post-authentication escalation path for anyone who obtains admin credentials.
Description
A vulnerability in the Pulse Connect Secure < 9.1R8.2 admin web interface could allow an authenticated attacker to upload custom template to perform an arbitrary code execution.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityThe flaw gives authenticated admin-level code execution on a security appliance and is in CISA KEV with very high EPSS, though it requires prior admin credentials.
What it is
Pulse Connect Secure before 9.1R8.2 allows an authenticated attacker to upload a custom template through the admin web interface, resulting in arbitrary code execution. Because the flaw is in the administrative interface and yields code execution on the appliance, it is a serious post-authentication escalation path for anyone who obtains admin credentials.
Impact
An attacker with admin access can execute arbitrary code on the Connect Secure appliance, gaining control of the device and potentially reaching credentials, VPN sessions and internal network paths it protects.
Attack surface
Reached over the network through the admin web interface (AV:N, PR:H, UI:N); the attacker must already hold high-privileged administrative credentials, and no user interaction is required.
Exploitation
Listed in CISA KEV since 2021-11-03 with a required action to apply vendor updates, and EPSS shows a 30-day probability of about 0.91 (99.8th percentile), indicating active exploitation is expected. No ransomware campaign use is recorded.
What to do
- Upgrade Pulse Connect Secure to 9.1R8.2 or later per vendor advisory SA44588.
- Restrict admin web interface access to trusted management networks and disable it from internet-facing exposure.
- Enforce strong unique admin credentials and MFA, and rotate credentials if compromise is suspected.
- Audit and remove any unauthorized custom templates or files on the appliance.
- Monitor vendor advisories for follow-up fixes affecting the same interface.
Detection
- Review appliance logs for custom template uploads or unexpected file writes via the admin web interface.
- Alert on admin interface logins from unusual source IPs or outside normal administrative hours.
- Hunt for unexpected processes or outbound connections originating from the Connect Secure appliance.
- Compare template and configuration files against known-good baselines to spot unauthorized modifications.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2020-8243 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Ivanti Pulse Connect Secure Code Execution Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44588 | Vendor Advisory |
| https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44588 | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-8243 | US Government Resource |
Track CVE-2020-8243 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-8243), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.