← Vulnerability feed

Vulnerability record · CVE-2020-8243 · published 30 September 2020

CVE-2020-8243: Pulse Connect Secure admin interface template upload code execution

Ivanti · Connect Secure

Pulse Connect Secure before 9.1R8.2 allows an authenticated attacker to upload a custom template through the admin web interface, resulting in arbitrary code execution. Because the flaw is in the administrative interface and yields code execution on the appliance, it is a serious post-authentication escalation path for anyone who obtains admin credentials.

7.2 CVSS 3.1 High CISA KEV since 3 Nov 2021 EPSS 91% · top 0.2% CWE-94 · Code injection
7.2CVSS 3.1 base score, v2 6.5
91%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
2Affected product versions listed by NVD
3References
17 Jun 2026Last modified by NVD

Description

A vulnerability in the Pulse Connect Secure < 9.1R8.2 admin web interface could allow an authenticated attacker to upload custom template to perform an arbitrary code execution.

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityThe flaw gives authenticated admin-level code execution on a security appliance and is in CISA KEV with very high EPSS, though it requires prior admin credentials.

What it is

Pulse Connect Secure before 9.1R8.2 allows an authenticated attacker to upload a custom template through the admin web interface, resulting in arbitrary code execution. Because the flaw is in the administrative interface and yields code execution on the appliance, it is a serious post-authentication escalation path for anyone who obtains admin credentials.

Impact

An attacker with admin access can execute arbitrary code on the Connect Secure appliance, gaining control of the device and potentially reaching credentials, VPN sessions and internal network paths it protects.

Attack surface

Reached over the network through the admin web interface (AV:N, PR:H, UI:N); the attacker must already hold high-privileged administrative credentials, and no user interaction is required.

Exploitation

Listed in CISA KEV since 2021-11-03 with a required action to apply vendor updates, and EPSS shows a 30-day probability of about 0.91 (99.8th percentile), indicating active exploitation is expected. No ransomware campaign use is recorded.

What to do

  • Upgrade Pulse Connect Secure to 9.1R8.2 or later per vendor advisory SA44588.
  • Restrict admin web interface access to trusted management networks and disable it from internet-facing exposure.
  • Enforce strong unique admin credentials and MFA, and rotate credentials if compromise is suspected.
  • Audit and remove any unauthorized custom templates or files on the appliance.
  • Monitor vendor advisories for follow-up fixes affecting the same interface.

Detection

  • Review appliance logs for custom template uploads or unexpected file writes via the admin web interface.
  • Alert on admin interface logins from unusual source IPs or outside normal administrative hours.
  • Hunt for unexpected processes or outbound connections originating from the Connect Secure appliance.
  • Compare template and configuration files against known-good baselines to spot unauthorized modifications.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2020-8243 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Ivanti Pulse Connect Secure Code Execution Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-8243 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2021-22893Ivanti Pulse Connect Secure authentication bypass and use-after-free enabling RCEPulse Connect Secure 9.0R3/9.1R1 and higher contains an authentication bypass exposed through the Windows File Share Browser and Pulse Secure Collabo…KEVEPSS 47%analysed10.0CVE-2019-11510Pulse Connect Secure path traversal allows unauthenticated file readPulse Connect Secure versions 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4 contain a path traversal (CWE-22) flaw. An unauthentica…KEVEPSS 100%analysed9.8CVE-2025-22457Ivanti Connect Secure, Policy Secure and ZTA Gateways stack buffer overflow RCEA stack-based buffer overflow (CWE-121/CWE-787) in Ivanti Connect Secure, Policy Secure and ZTA Gateways allows a remote, unauthenticated attacker to…KEVEPSS 100%analysed9.1CVE-2024-21887Ivanti Connect Secure and Policy Secure web component command injectionIvanti Connect Secure and Policy Secure (9.x, 22.x) contain a command injection flaw (CWE-77) in web components. An authenticated administrator can s…KEVEPSS 100%analysed9.0CVE-2025-0282Ivanti Connect Secure stack buffer overflow enables unauthenticated RCEA stack-based buffer overflow (CWE-121/CWE-787) in Ivanti Connect Secure, Policy Secure and Neurons for ZTA gateways lets a remote, unauthenticated a…KEVEPSS 100%analysed8.8CVE-2021-22894Pulse Connect Secure buffer overflow allows root code executionPulse Connect Secure before 9.1R11.4 contains a buffer overflow reachable through a maliciously crafted meeting room. A remote authenticated attacker…KEVEPSS 41%analysed8.8CVE-2021-22899Pulse Connect Secure command injection via Windows Resource ProfilesPulse Connect Secure before 9.1R11.4 contains a command injection flaw (CWE-77) in the Windows Resource Profiles feature. An attacker who can authent…KEVEPSS 23%analysed8.2CVE-2024-21893Ivanti Connect Secure SAML SSRF allows unauthenticated resource accessThe SAML component of Ivanti Connect Secure, Policy Secure and Neurons for ZTA contains a server-side request forgery flaw that lets an attacker reac…KEVEPSS 100%analysed

Source: NIST National Vulnerability Database (record CVE-2020-8243), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.