CVE-2020-12880
Summary
| CVE | CVE-2020-12880 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-07-27 23:15:00 UTC |
| Updated | 2024-01-13 04:43:00 UTC |
| Description | An issue was discovered in Pulse Policy Secure (PPS) and Pulse Connect Secure (PCS) Virtual Appliance before 9.1R8. By manipulating a certain kernel boot parameter, it can be tricked into dropping into a root shell in a pre-install phase where the entire source code of the appliance is available and can be retrieved. (The source code is otherwise inaccessible because the appliance has its hard disks encrypted, and no root shell is available during normal operation.) |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ivanti | Policy Secure | 9.1 | r1 | All | All |
| Application | Ivanti | Policy Secure | 9.1 | r2 | All | All |
| Application | Ivanti | Policy Secure | 9.1 | r3 | All | All |
| Application | Ivanti | Policy Secure | 9.1 | r3.1 | All | All |
| Application | Ivanti | Policy Secure | 9.1 | r4 | All | All |
| Application | Ivanti | Policy Secure | 9.1 | r4.1 | All | All |
| Application | Ivanti | Policy Secure | 9.1 | r4.2 | All | All |
| Application | Ivanti | Policy Secure | 9.1 | r5 | All | All |
| Application | Ivanti | Policy Secure | 9.1 | r6 | All | All |
| Application | Ivanti | Policy Secure | 9.1 | r7 | All | All |
| Application | Pulsesecure | Pulse Connect Secure | 9.1 | - | All | All |
| Application | Pulsesecure | Pulse Connect Secure | 9.1 | r1 | All | All |
| Application | Pulsesecure | Pulse Connect Secure | 9.1 | r2 | All | All |
| Application | Pulsesecure | Pulse Connect Secure | 9.1 | r3 | All | All |
| Application | Pulsesecure | Pulse Connect Secure | 9.1 | r4 | All | All |
| Application | Pulsesecure | Pulse Connect Secure | 9.1 | r4.1 | All | All |
| Application | Pulsesecure | Pulse Connect Secure | 9.1 | r4.2 | All | All |
| Application | Pulsesecure | Pulse Connect Secure | 9.1 | r4.3 | All | All |
| Application | Pulsesecure | Pulse Connect Secure | 9.1 | r5 | All | All |
| Application | Pulsesecure | Pulse Connect Secure | 9.1 | r6 | All | All |
| Application | Pulsesecure | Pulse Connect Secure | 9.1 | r7 | All | All |
| Application | Pulsesecure | Pulse Connect Secure | 9.1 | - | All | All |
| Application | Pulsesecure | Pulse Connect Secure | 9.1 | r1 | All | All |
| Application | Pulsesecure | Pulse Connect Secure | 9.1 | r2 | All | All |
| Application | Pulsesecure | Pulse Connect Secure | 9.1 | r3 | All | All |
| Application | Pulsesecure | Pulse Connect Secure | 9.1 | r4 | All | All |
| Application | Pulsesecure | Pulse Connect Secure | 9.1 | r4.1 | All | All |
| Application | Pulsesecure | Pulse Connect Secure | 9.1 | r4.2 | All | All |
| Application | Pulsesecure | Pulse Connect Secure | 9.1 | r4.3 | All | All |
| Application | Pulsesecure | Pulse Connect Secure | 9.1 | r5 | All | All |
| Application | Pulsesecure | Pulse Connect Secure | 9.1 | r6 | All | All |
| Application | Pulsesecure | Pulse Connect Secure | 9.1 | r7 | All | All |
| Application | Pulsesecure | Pulse Connect Secure | All | All | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 9.1 | r1 | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 9.1 | r2 | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 9.1 | r3 | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 9.1 | r3.1 | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 9.1 | r4 | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 9.1 | r4.1 | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 9.1 | r4.2 | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 9.1 | r5 | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 9.1 | r6 | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 9.1 | r7 | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 9.1 | r1 | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 9.1 | r2 | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 9.1 | r3 | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 9.1 | r3.1 | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 9.1 | r4 | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 9.1 | r4.1 | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 9.1 | r4.2 | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 9.1 | r5 | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 9.1 | r6 | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 9.1 | r7 | All | All |
| Application | Pulsesecure | Pulse Policy Secure | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Public KB - SA44516 - 2020-07: Security Bulletin: Multiple Vulnerabilities Resolved in Pulse Connect Secure / Pulse Policy Secure 9.1R8 | CONFIRM | kb.pulsesecure.net | Vendor Advisory |
| Public KB - Home | MISC | kb.pulsesecure.net | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.