Permissions, Privileges, and Access Controls in Ivanti Policy Secure (formerly Pulse Policy Secure) and Ivanti Connect Secure (formerly Pulse Connect Secure) - CVE-2020-12880
Published: July 27, 2020
Vulnerability identifier: #VU31944
CSH Severity: Low
CVSS v4: 7 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-12880
CWE-ID: CWE-264
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local attacker to escalate privileges on the system.
The vulnerability exists due to improper security restrictions. An attacker with physical access to the device can manipulate kernel boot parameter to gain the root access of VA Appliances.
Affected software
Ivanti Policy Secure (formerly Pulse Policy Secure)
Ivanti Connect Secure (formerly Pulse Connect Secure)
Ivanti Connect Secure (formerly Pulse Connect Secure)
How to mitigate CVE-2020-12880
Install updates from vendor's website.
Ivanti Policy Secure (formerly Pulse Policy Secure) - update to 9.1R8
Ivanti Connect Secure (formerly Pulse Connect Secure) - update to 9.1R8
Ivanti Connect Secure (formerly Pulse Connect Secure) - update to 9.1R8