Medium severity5.5NVD Advisory· Published Jul 27, 2020· Updated Jun 17, 2026
CVE-2020-12880
CVE-2020-12880
Description
An issue was discovered in Pulse Policy Secure (PPS) and Pulse Connect Secure (PCS) Virtual Appliance before 9.1R8. By manipulating a certain kernel boot parameter, it can be tricked into dropping into a root shell in a pre-install phase where the entire source code of the appliance is available and can be retrieved. (The source code is otherwise inaccessible because the appliance has its hard disks encrypted, and no root shell is available during normal operation.)
Affected products
26cpe:2.3:a:ivanti:connect_secure:9.1:-:*:*:*:*:*:*+ 10 more
- cpe:2.3:a:ivanti:connect_secure:9.1:-:*:*:*:*:*:*
- cpe:2.3:a:ivanti:connect_secure:9.1:r1:*:*:*:*:*:*
- cpe:2.3:a:ivanti:connect_secure:9.1:r2:*:*:*:*:*:*
- cpe:2.3:a:ivanti:connect_secure:9.1:r3:*:*:*:*:*:*
- cpe:2.3:a:ivanti:connect_secure:9.1:r4.1:*:*:*:*:*:*
- cpe:2.3:a:ivanti:connect_secure:9.1:r4.2:*:*:*:*:*:*
- cpe:2.3:a:ivanti:connect_secure:9.1:r4.3:*:*:*:*:*:*
- cpe:2.3:a:ivanti:connect_secure:9.1:r4:*:*:*:*:*:*
- cpe:2.3:a:ivanti:connect_secure:9.1:r5:*:*:*:*:*:*
- cpe:2.3:a:ivanti:connect_secure:9.1:r6:*:*:*:*:*:*
- cpe:2.3:a:ivanti:connect_secure:9.1:r7:*:*:*:*:*:*
cpe:2.3:a:ivanti:policy_secure:9.1:r1:*:*:*:*:*:*+ 9 more
- cpe:2.3:a:ivanti:policy_secure:9.1:r1:*:*:*:*:*:*
- cpe:2.3:a:ivanti:policy_secure:9.1:r2:*:*:*:*:*:*
- cpe:2.3:a:ivanti:policy_secure:9.1:r3.1:*:*:*:*:*:*
- cpe:2.3:a:ivanti:policy_secure:9.1:r3:*:*:*:*:*:*
- cpe:2.3:a:ivanti:policy_secure:9.1:r4.1:*:*:*:*:*:*
- cpe:2.3:a:ivanti:policy_secure:9.1:r4.2:*:*:*:*:*:*
- cpe:2.3:a:ivanti:policy_secure:9.1:r4:*:*:*:*:*:*
- cpe:2.3:a:ivanti:policy_secure:9.1:r5:*:*:*:*:*:*
- cpe:2.3:a:ivanti:policy_secure:9.1:r6:*:*:*:*:*:*
- cpe:2.3:a:ivanti:policy_secure:9.1:r7:*:*:*:*:*:*
cpe:2.3:a:pulsesecure:pulse_connect_secure:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:pulsesecure:pulse_connect_secure:*:*:*:*:*:*:*:*range: <=9.0
- (no CPE)range: <9.1R8
cpe:2.3:a:pulsesecure:pulse_policy_secure:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:pulsesecure:pulse_policy_secure:*:*:*:*:*:*:*:*range: <=9.0
- (no CPE)range: <9.1R8
- Pulse Secure/Pulse Policy Secure (PPS) and Pulse Connect Secure (PCS) Virtual Appliancedescription
Patches
Vulnerability mechanics
References
2- kb.pulsesecure.netnvdVendor Advisory
- kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44516nvdVendor Advisory
News mentions
0No linked articles in our index yet.