VYPR
Medium severity5.5NVD Advisory· Published Jul 27, 2020· Updated Jun 17, 2026

CVE-2020-12880

CVE-2020-12880

Description

An issue was discovered in Pulse Policy Secure (PPS) and Pulse Connect Secure (PCS) Virtual Appliance before 9.1R8. By manipulating a certain kernel boot parameter, it can be tricked into dropping into a root shell in a pre-install phase where the entire source code of the appliance is available and can be retrieved. (The source code is otherwise inaccessible because the appliance has its hard disks encrypted, and no root shell is available during normal operation.)

Affected products

26
  • cpe:2.3:a:ivanti:connect_secure:9.1:-:*:*:*:*:*:*+ 10 more
    • cpe:2.3:a:ivanti:connect_secure:9.1:-:*:*:*:*:*:*
    • cpe:2.3:a:ivanti:connect_secure:9.1:r1:*:*:*:*:*:*
    • cpe:2.3:a:ivanti:connect_secure:9.1:r2:*:*:*:*:*:*
    • cpe:2.3:a:ivanti:connect_secure:9.1:r3:*:*:*:*:*:*
    • cpe:2.3:a:ivanti:connect_secure:9.1:r4.1:*:*:*:*:*:*
    • cpe:2.3:a:ivanti:connect_secure:9.1:r4.2:*:*:*:*:*:*
    • cpe:2.3:a:ivanti:connect_secure:9.1:r4.3:*:*:*:*:*:*
    • cpe:2.3:a:ivanti:connect_secure:9.1:r4:*:*:*:*:*:*
    • cpe:2.3:a:ivanti:connect_secure:9.1:r5:*:*:*:*:*:*
    • cpe:2.3:a:ivanti:connect_secure:9.1:r6:*:*:*:*:*:*
    • cpe:2.3:a:ivanti:connect_secure:9.1:r7:*:*:*:*:*:*
  • cpe:2.3:a:ivanti:policy_secure:9.1:r1:*:*:*:*:*:*+ 9 more
    • cpe:2.3:a:ivanti:policy_secure:9.1:r1:*:*:*:*:*:*
    • cpe:2.3:a:ivanti:policy_secure:9.1:r2:*:*:*:*:*:*
    • cpe:2.3:a:ivanti:policy_secure:9.1:r3.1:*:*:*:*:*:*
    • cpe:2.3:a:ivanti:policy_secure:9.1:r3:*:*:*:*:*:*
    • cpe:2.3:a:ivanti:policy_secure:9.1:r4.1:*:*:*:*:*:*
    • cpe:2.3:a:ivanti:policy_secure:9.1:r4.2:*:*:*:*:*:*
    • cpe:2.3:a:ivanti:policy_secure:9.1:r4:*:*:*:*:*:*
    • cpe:2.3:a:ivanti:policy_secure:9.1:r5:*:*:*:*:*:*
    • cpe:2.3:a:ivanti:policy_secure:9.1:r6:*:*:*:*:*:*
    • cpe:2.3:a:ivanti:policy_secure:9.1:r7:*:*:*:*:*:*
  • cpe:2.3:a:pulsesecure:pulse_connect_secure:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:pulsesecure:pulse_connect_secure:*:*:*:*:*:*:*:*range: <=9.0
    • (no CPE)range: <9.1R8
  • cpe:2.3:a:pulsesecure:pulse_policy_secure:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:pulsesecure:pulse_policy_secure:*:*:*:*:*:*:*:*range: <=9.0
    • (no CPE)range: <9.1R8
  • Pulse Secure/Pulse Policy Secure (PPS) and Pulse Connect Secure (PCS) Virtual Appliancedescription

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.