CVE-2020-8256

MEDIUM

Pulse Connect Secure <9.1R8.2 - XXE

Title source: llm
STIX 2.1

Description

A vulnerability in the Pulse Connect Secure < 9.1R8.2 admin web interface could allow an authenticated attacker to gain arbitrary file reading access through Pulse Collaboration via XML External Entity (XXE) vulnerability.

Scores

CVSS v3 4.9
EPSS 0.0391
EPSS Percentile 88.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-611
Status published
Products (2)
ivanti/connect_secure 9.1 (13 CPE variants)
pulsesecure/pulse_connect_secure < 9.0
Published Sep 30, 2020
Tracked Since Feb 18, 2026