Record summary

CVE-2020-8218 has a selected CVSS score of 7.2 (high); EIP currently links 1 repository PoC. CISA lists CVE-2020-8218 in KEV.

Description

A code injection vulnerability exists in Pulse Connect Secure <9.1R8 that allows an attacker to crafted a URI to perform an arbitrary code execution via the admin web interface.

Description source: CVE List

Exploitation context

Known exploitation

CISA KEV
Listed · Mar 7, 2022 · CISA
VulnCheck KEV
Listed · Dec 7, 2020 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Repository PoCs
1

CISA SSVC decision

ExploitationActive
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 4, 2025 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus
CISAVersion data not supplied

Pulse Connect Secure

CVE ListFixed in 9.1R8affected

Proofs of concept

1

Repository PoCs

GitHubwithdk/pulse-gosecure-rce-pocRepository PoCby withdkStars: 21Not analyzed4 files

47.5 KiB

GitHub

PoC details

References

4