CVE-2020-12880
An issue was discovered in Pulse Policy Secure (PPS) and Pulse Connect Secure (PCS) Virtual Appliance before 9.1R8.
Does this matter?
Lower severity and a low EPSS score (0.48%). Track it; it rarely justifies an emergency change on its own.
Description
An issue was discovered in Pulse Policy Secure (PPS) and Pulse Connect Secure (PCS) Virtual Appliance before 9.1R8. By manipulating a certain kernel boot parameter, it can be tricked into dropping into a root shell in a pre-install phase where the entire source code of the appliance is available and can be retrieved. (The source code is otherwise inaccessible because the appliance has its hard disks encrypted, and no root shell is available during normal operation.)
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.48% probability · 40th percentile
- CISA KEV
- Not listed
- Affected
- ivanti/connect secure · pulsesecure/pulse connect secure · ivanti/policy secure · pulsesecure/pulse policy secure
- Source
- cve@mitre.org
References
- https://kb.pulsesecure.net/?atype=saVendor Advisory
- https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44516Vendor Advisory
- https://kb.pulsesecure.net/?atype=saVendor Advisory
- https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44516Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.