CVE-2020-8260
28.10.2020, 13:15
A vulnerability in the Pulse Connect Secure < 9.1R9 admin web interface could allow an authenticated attacker to perform an arbitrary code execution using uncontrolled gzip extraction.Enginsight
Vendor | Product | Version |
---|---|---|
ivanti | connect_secure | 𝑥 ≤ 9.0 |
ivanti | connect_secure | 9.1 |
ivanti | connect_secure | 9.1:r1.0 |
ivanti | connect_secure | 9.1:r2.0 |
ivanti | connect_secure | 9.1:r3.0 |
ivanti | connect_secure | 9.1:r4.0 |
ivanti | connect_secure | 9.1:r4.1 |
ivanti | connect_secure | 9.1:r4.2 |
ivanti | connect_secure | 9.1:r4.3 |
ivanti | connect_secure | 9.1:r5.0 |
ivanti | connect_secure | 9.1:r6.0 |
ivanti | connect_secure | 9.1:r7.0 |
ivanti | connect_secure | 9.1:r8.0 |
ivanti | connect_secure | 9.1:r8.1 |
ivanti | connect_secure | 9.1:r8.2 |
ivanti | connect_secure | 9.1:r8.4 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References