CVE Vulnerabilities

CVE-2020-8255

Published: Oct 28, 2020 | Modified: Aug 17, 2021
CVSS 3.x
4.9
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

A vulnerability in the Pulse Connect Secure < 9.1R9 admin web interface could allow an authenticated attacker to perform an arbitrary file reading vulnerability is fixed using encrypted URL blacklisting that prevents these messages.

Affected Software

Name Vendor Start Version End Version
Pulse_secure_desktop_client Pulsesecure * 9.1 (excluding)
Pulse_secure_desktop_client Pulsesecure 9.1 (including) 9.1 (including)
Pulse_secure_desktop_client Pulsesecure 9.1-r1 (including) 9.1-r1 (including)
Pulse_secure_desktop_client Pulsesecure 9.1-r2 (including) 9.1-r2 (including)
Pulse_secure_desktop_client Pulsesecure 9.1-r3 (including) 9.1-r3 (including)
Pulse_secure_desktop_client Pulsesecure 9.1-r3.1 (including) 9.1-r3.1 (including)
Pulse_secure_desktop_client Pulsesecure 9.1-r4 (including) 9.1-r4 (including)
Pulse_secure_desktop_client Pulsesecure 9.1-r4.1 (including) 9.1-r4.1 (including)
Pulse_secure_desktop_client Pulsesecure 9.1-r4.2 (including) 9.1-r4.2 (including)
Pulse_secure_desktop_client Pulsesecure 9.1-r5 (including) 9.1-r5 (including)
Pulse_secure_desktop_client Pulsesecure 9.1-r6 (including) 9.1-r6 (including)
Pulse_secure_desktop_client Pulsesecure 9.1-r7 (including) 9.1-r7 (including)
Pulse_secure_desktop_client Pulsesecure 9.1-r7.1 (including) 9.1-r7.1 (including)
Pulse_secure_desktop_client Pulsesecure 9.1-r8 (including) 9.1-r8 (including)
Pulse_secure_desktop_client Pulsesecure 9.1-r8.2 (including) 9.1-r8.2 (including)

References