CVE-2020-8260

A vulnerability in the Pulse Connect Secure < 9.1R9 admin web interface could allow an authenticated attacker to perform an arbitrary code execution using uncontrolled gzip extraction.

  • Published Oct 28, 2020
  • CVSS 7.2 high
  • 96.5% chance of exploitation in the next 30 days (EPSS)
  • In CISA's Known Exploited Vulnerabilities catalog
  • A Metasploit module exploits it

Affected software

CVE-2020-8260 at the National Vulnerability Database