A vulnerability in the Pulse Connect Secure < 9.1R8.2 admin web interface could allow an authenticated attacker to upload custom template to perform an arbitrary code execution.
2020-09-30T18:15:29.070
2025-02-12T19:56:52.180
Analyzed
CVSSv3.1: 7.2 (HIGH)
AV:N/AC:L/Au:S/C:P/I:P/A:P
8.0
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | ivanti | connect_secure | ≤ 9.0 | Yes |
Application | ivanti | connect_secure | 9.1 | Yes |
Application | ivanti | connect_secure | 9.1 | Yes |
Application | ivanti | connect_secure | 9.1 | Yes |
Application | ivanti | connect_secure | 9.1 | Yes |
Application | ivanti | connect_secure | 9.1 | Yes |
Application | ivanti | connect_secure | 9.1 | Yes |
Application | ivanti | connect_secure | 9.1 | Yes |
Application | ivanti | connect_secure | 9.1 | Yes |
Application | ivanti | connect_secure | 9.1 | Yes |
Application | ivanti | connect_secure | 9.1 | Yes |
Application | ivanti | connect_secure | 9.1 | Yes |
Application | ivanti | connect_secure | 9.1 | Yes |
Application | ivanti | connect_secure | 9.1 | Yes |
Application | ivanti | policy_secure | ≤ 9.0 | Yes |
Application | ivanti | policy_secure | 9.1 | Yes |
Application | ivanti | policy_secure | 9.1 | Yes |
Application | ivanti | policy_secure | 9.1 | Yes |
Application | ivanti | policy_secure | 9.1 | Yes |
Application | ivanti | policy_secure | 9.1 | Yes |
Application | ivanti | policy_secure | 9.1 | Yes |
Application | ivanti | policy_secure | 9.1 | Yes |
Application | ivanti | policy_secure | 9.1 | Yes |
Application | ivanti | policy_secure | 9.1 | Yes |
Application | ivanti | policy_secure | 9.1 | Yes |
Application | ivanti | policy_secure | 9.1 | Yes |
Application | ivanti | policy_secure | 9.1 | Yes |
Application | ivanti | policy_secure | 9.1 | Yes |