CVE-2020-8260 PUBLISHED KEV CVSS 6.5 MEDIUM

A vulnerability in the Pulse Connect Secure < 9.1R9 admin web interface could allow an authenticated attacker to perform an arbitrary code execution using uncontrolled gzip extraction.

EPSS 75.89% · 98.9th percentile

Risk Scores

CVSS v2.0
6.5
EPSS Score
75.89%
98.9th percentile

Affected Products

VendorProductVersions
n/aPulse Connect Secure / Pulse Policy Secure9.1R9
ivanticonnect_secure0, 9.1, 9.1

Timeline

References

Open in Interactive Console →