CVE-2020-8218

Pulse Connect Secure

Published 30 Jul 2020 · updated 17 Jun 2026 · Analyzed

7.2 High · CVSS 3.1, NVD

Exploited in the wild

CISA added this to its Known Exploited Vulnerabilities catalog on 7 Mar 2022, with a remediation deadline of 7 Sept 2022 for US federal agencies.

Required action: Apply updates per vendor instructions.

Description

A code injection vulnerability exists in Pulse Connect Secure <9.1R8 that allows an attacker to crafted a URI to perform an arbitrary code execution via the admin web interface.

References