target entity

Pulse Connect Secure

8 source-linked records in the current knowledge graph.

high

CVE-2020-8218: Pulse Connect Secure Code Injection Vulnerability

A code injection vulnerability exists in Pulse Connect Secure that allows an attacker to crafted a URI to perform an arbitrary code execution via the admin web interface. Required action: Apply updates per vendor instructions.

CVE-2020-8218EPSS 32.7%Pulse Connect SecurePulse Secure
CISA KEV ↗ · unattributed attribution
high

CVE-2020-8243: Ivanti Pulse Connect Secure Code Execution Vulnerability

Ivanti Pulse Connect Secure contains an unspecified vulnerability in the admin web interface that could allow an authenticated attacker to upload a custom template to perform code execution. Required action: Apply updates per vendor instructions.

CVE-2020-8243EPSS 90.8%IvantiPulse Connect Secure
CISA KEV ↗ · unattributed attribution
high

CVE-2021-22900: Ivanti Pulse Connect Secure Unrestricted File Upload Vulnerability

Ivanti Pulse Connect Secure contains an unrestricted file upload vulnerability that allows an authenticated administrator to perform a file write via a maliciously crafted archive upload in the administrator web interface. Required action: Apply updates per vendor instructions.

CVE-2021-22900EPSS 14.1%IvantiPulse Connect Secure
CISA KEV ↗ · unattributed attribution