Skip to main content
Mallory
HighCISA KEVExploited in the wildPublic exploit

Ivanti Pulse Connect Secure Admin Web Interface Template Upload RCE

IdentifiersCVE-2020-8243CWE-94· Improper Control of Generation of…

CVE-2020-8243 is an arbitrary code execution vulnerability in the admin web interface of Pulse Connect Secure (now Ivanti Pulse Connect Secure) versions prior to 9.1R8.2. According to the provided content, an authenticated attacker can upload a custom template through the administrative interface and use that capability to execute arbitrary code on the appliance. The issue affects the management plane rather than the end-user VPN portal and was significant enough to be repeatedly cited by CISA, Ivanti, and incident responders as one of several Pulse Secure flaws leveraged in real-world intrusions. The available content does not identify the exact vulnerable function or request handler beyond the admin web interface custom-template upload mechanism.

Share:
For your environment

Are you exposed to this one?

Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.

ANALYST BRIEF

Impact, mitigation & remediation

What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.

Impact

What an attacker gets, and what they’ve been doing with it.

Successful exploitation allows arbitrary code execution on the affected Pulse Connect Secure appliance. In operational terms, this can enable full compromise of the VPN gateway, including installation of webshells or other persistence mechanisms, credential theft, authentication and MFA bypass support through follow-on tooling, and use of the appliance as a foothold for broader intrusion activity. The supplied reporting also places CVE-2020-8243 among vulnerabilities used in campaigns affecting government, critical infrastructure, defense, financial, and private-sector organizations.

Mitigation

If you can’t patch tonight, do this now.

If immediate patching is not possible, restrict exposure of the administrative web interface to trusted management networks only, disable or tightly control administrative access, enforce strong authentication for administrators, and monitor for suspicious template-upload or admin-interface activity. Given the documented history of exploitation of Pulse Secure appliances, defenders should also inspect unauthenticated and administrative request logs, hunt for persistence or modified files on the appliance, and assume credential exposure if integrity checks indicate compromise. Mitigation information specific to disabling the vulnerable feature is not available in the provided content.

Remediation

Patch, then assume compromise.

Upgrade Pulse Connect Secure to a fixed release. The provided content states the vulnerability affects versions earlier than 9.1R8.2, so remediation is to update to 9.1R8.2 or later, and preferably to later vendor-supported releases where applicable. Because this vulnerability was observed in exploitation chains, remediation should also include running Ivanti's Pulse Connect Secure Integrity Tool or equivalent integrity checks, reviewing the appliance for unauthorized modifications or webshells, and resetting credentials associated with the Pulse Secure environment if compromise is suspected.
PUBLIC EXPLOITS

Exploits

No public exploits tracked yet. Mallory keeps watching.

VALID 0 / 0 TOTALView more in app

No public exploit code observed for this vulnerability.

EXPOSURE SURFACE

Affected products & vendors

Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.

VendorProductType
IvantiConnect Secureapplication
IvantiPolicy Secureapplication

Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets are affected, which adversaries are exploiting it right now, which detections to deploy, and what to do tonight.
Exposure mapping

Query your assets running an affected version, and investigate the blast radius.

Threat actor evidence

Every observed campaign linking this CVE to a named adversary.

Associated malware22

Malware families riding this exploit, with evidence and IOCs.

Detection signatures1

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Vendor-by-vendor mapping

Cross-references every affected SKU, including bundled OEM variants.

Social activity

Community discussion across Reddit, Mastodon, and other social sources.