Permissions, Privileges, and Access Controls in Ivanti Policy Secure (formerly Pulse Policy Secure) and Ivanti Connect Secure (formerly Pulse Connect Secure) - CVE-2020-12880

 

Permissions, Privileges, and Access Controls in Ivanti Policy Secure (formerly Pulse Policy Secure) and Ivanti Connect Secure (formerly Pulse Connect Secure) - CVE-2020-12880

Published: July 27, 2020


Vulnerability identifier: #VU31944
CSH Severity: Low
CVSS v4: 7 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-12880
CWE-ID: CWE-264
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to escalate privileges on the system.

The vulnerability exists due to improper security restrictions. An attacker with physical access to the device can manipulate kernel boot parameter to gain the root access of VA Appliances.


Affected software

Ivanti Policy Secure (formerly Pulse Policy Secure)
Ivanti Connect Secure (formerly Pulse Connect Secure)

How to mitigate CVE-2020-12880

Install updates from vendor's website.

Ivanti Policy Secure (formerly Pulse Policy Secure) - update to 9.1R8
Ivanti Connect Secure (formerly Pulse Connect Secure) - update to 9.1R8

External References

Related Security Bulletins