Improper access control in Ivanti Policy Secure (formerly Pulse Policy Secure) and Ivanti Connect Secure (formerly Pulse Connect Secure) - CVE-2020-15408
Published: July 27, 2020
Vulnerability identifier: #VU31948
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-15408
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions. A remote authenticated user can access the admin panel of the device via the end user web interface through rewrite.
Affected software
Ivanti Policy Secure (formerly Pulse Policy Secure)
Ivanti Connect Secure (formerly Pulse Connect Secure)
Ivanti Connect Secure (formerly Pulse Connect Secure)
How to mitigate CVE-2020-15408
Install updates from vendor's website.
Ivanti Policy Secure (formerly Pulse Policy Secure) - update to 9.1R8
Ivanti Connect Secure (formerly Pulse Connect Secure) - update to 9.1R8
Ivanti Connect Secure (formerly Pulse Connect Secure) - update to 9.1R8