CVE-2020-8241

moderate-risk
Published 2020-10-28

A vulnerability in the Pulse Secure Desktop Client < 9.1R9 could allow the attacker to perform a MITM Attack if end users are convinced to connect to a malicious server.

Do I need to act?

~
3.5% chance of exploitation in next 30 days
EPSS score — moderate exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
7
CVSS 7.5/10 High
NETWORK / HIGH complexity

Affected Products (14)

Pulse Secure Desktop Client
Pulse Secure Desktop Client
Pulse Secure Desktop Client
Pulse Secure Desktop Client
Pulse Secure Desktop Client
Pulse Secure Desktop Client
Pulse Secure Desktop Client
Pulse Secure Desktop Client
Pulse Secure Desktop Client
Pulse Secure Desktop Client
Pulse Secure Desktop Client
Pulse Secure Desktop Client
Pulse Secure Desktop Client
Pulse Secure Desktop Client

Affected Vendors

47
/ 100
moderate-risk
Severity 22/34 · High
Exploitability 7/34 · Low
Exposure 18/34 · Moderate