Skip to content
COOEY

EXPOSURES › CVE-2020-8218

CVE-2020-8218

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-03-07 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2020-8218 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 rceexploited-in-wildunpatched

Pulse Connect Secure's admin web interface allowed arbitrary code execution via crafted URIs due to a code injection vulnerability.

An attacker could execute arbitrary code on the admin web interface by crafting a malicious URI, enabling full system compromise. DIB orgs must ensure all Pulse Secure devices are patched immediately, as this vulnerability was actively exploited in the wild and represents a severe breach of secure configuration and patch management. Failure to patch exposes sensitive data and undermines compliance with CMMC/NIST 800-171 requirements for vulnerability management.

Shame score — A critical code injection flaw allowing arbitrary code execution was actively exploited in the wild, indicating severe negligence in patch management and security hygiene.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

A code injection vulnerability exists in Pulse Connect Secure that allows an attacker to crafted a URI to perform an arbitrary code execution via the admin web interface.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.