EXPOSURES › CVE-2020-8218
CVE-2020-8218
HIGH ⌖ ON CISA KEV · EXPLOITEDPulse Connect Secure's admin web interface allowed arbitrary code execution via crafted URIs due to a code injection vulnerability.
An attacker could execute arbitrary code on the admin web interface by crafting a malicious URI, enabling full system compromise. DIB orgs must ensure all Pulse Secure devices are patched immediately, as this vulnerability was actively exploited in the wild and represents a severe breach of secure configuration and patch management. Failure to patch exposes sensitive data and undermines compliance with CMMC/NIST 800-171 requirements for vulnerability management.
Shame score — A critical code injection flaw allowing arbitrary code execution was actively exploited in the wild, indicating severe negligence in patch management and security hygiene.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A code injection vulnerability exists in Pulse Connect Secure that allows an attacker to crafted a URI to perform an arbitrary code execution via the admin web interface.