High severity7.2CISA KEVNVD Advisory· Published Oct 28, 2020· Updated Jun 17, 2026
CVE-2020-8260
CVE-2020-8260
Description
A vulnerability in the Pulse Connect Secure < 9.1R9 admin web interface could allow an authenticated attacker to perform an arbitrary code execution using uncontrolled gzip extraction.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
18cpe:2.3:a:ivanti:connect_secure:*:*:*:*:*:*:*:*+ 15 more
- cpe:2.3:a:ivanti:connect_secure:*:*:*:*:*:*:*:*range: <=9.0
- cpe:2.3:a:ivanti:connect_secure:9.1:-:*:*:*:*:*:*
- cpe:2.3:a:ivanti:connect_secure:9.1:r1.0:*:*:*:*:*:*
- cpe:2.3:a:ivanti:connect_secure:9.1:r2.0:*:*:*:*:*:*
- cpe:2.3:a:ivanti:connect_secure:9.1:r3.0:*:*:*:*:*:*
- cpe:2.3:a:ivanti:connect_secure:9.1:r4.0:*:*:*:*:*:*
- cpe:2.3:a:ivanti:connect_secure:9.1:r4.1:*:*:*:*:*:*
- cpe:2.3:a:ivanti:connect_secure:9.1:r4.2:*:*:*:*:*:*
- cpe:2.3:a:ivanti:connect_secure:9.1:r4.3:*:*:*:*:*:*
- cpe:2.3:a:ivanti:connect_secure:9.1:r5.0:*:*:*:*:*:*
- cpe:2.3:a:ivanti:connect_secure:9.1:r6.0:*:*:*:*:*:*
- cpe:2.3:a:ivanti:connect_secure:9.1:r7.0:*:*:*:*:*:*
- cpe:2.3:a:ivanti:connect_secure:9.1:r8.0:*:*:*:*:*:*
- cpe:2.3:a:ivanti:connect_secure:9.1:r8.1:*:*:*:*:*:*
- cpe:2.3:a:ivanti:connect_secure:9.1:r8.2:*:*:*:*:*:*
- cpe:2.3:a:ivanti:connect_secure:9.1:r8.4:*:*:*:*:*:*
- Pulse/Pulse Connect Securedescription
- Range: <9.1R9
Patches
Vulnerability mechanics
References
3- packetstormsecurity.com/files/160619/Pulse-Secure-VPN-Remote-Code-Execution.htmlnvdExploitThird Party AdvisoryVDB Entry
- kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44601nvdBroken LinkVendor Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
News mentions
0No linked articles in our index yet.