EXPOSURES › CVE-2020-8260
CVE-2020-8260
HIGH ⌖ ON CISA KEV · EXPLOITEDAn authenticated attacker could execute arbitrary code via uncontrolled gzip extraction in Ivanti Pulse Connect Secure.
Ivanti Pulse Connect Secure contained a code execution vulnerability allowing authenticated attackers to run arbitrary code through uncontrolled gzip extraction. This failure matters to DIB organizations because it represents an unpatched, actively exploited flaw (KEV) that could compromise secure access gateways, leading to data breaches or lateral movement. Organizations must ensure all Pulse Connect Secure instances are patched and monitored for exploitation attempts.
Shame score — The vulnerability was actively exploited in the wild (KEV) and allowed code execution, indicating a significant gap in patch management and threat detection.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Pulse Connect Secure contains an unspecified vulnerability that allows an authenticated attacker to perform code execution using uncontrolled gzip extraction.
"Pulse Connect Secure contains an unspecified vulnerability that allows an authenticated attacker to perform code execution using uncontrolled gzip extraction."
| PRODUCT | STATUS |
|---|---|
| Ivanti Neurons for ITSM (Formerly Service Manager) Ivanti |
Authorized |
| Ivanti Neurons for MDM (Formerly MobileIron) Ivanti |
Authorized |