Permissions, Privileges, and Access Controls in Ivanti Policy Secure (formerly Pulse Policy Secure) and Ivanti Connect Secure (formerly Pulse Connect Secure) - CVE-2020-8219
Published: July 27, 2020
Vulnerability details
The vulnerability allows a remote attacker to escalate privileges on the system.
The vulnerability exists due to application does not properly impose security restrictions, which leads to security restrictions bypass and privilege escalation. A user administrator can change the password of a full Administrator and escalate privileges on the system.
Affected software
Ivanti Connect Secure (formerly Pulse Connect Secure)
How to mitigate CVE-2020-8219
Ivanti Connect Secure (formerly Pulse Connect Secure) - update to 9.1R8