CVE-2018-6320 is a critical vulnerability affecting Pulse Secure Pulse Connect Secure and Pulse Policy Secure products, where the login.cgi component trusts unvalidated HTTP(S) Host headers. This flaw carries a CVSS score of 9.8 (Critical), indicating a network-exploitable vulnerability with low attack complexity that can lead to complete compromise of confidentiality, integrity, and availability. While not listed in CISA's KEV catalog, the vulnerability has garnered significant community discussion and media attention, with one article highlighting over 4,000 exposed vulnerable hosts. There is currently no public exploit code available in Metasploit or ExploitDB.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
8.1CPE matchmatch criteria | cpe:2.3:a:ivanti:connect_secure:8.1:*:*:*:*:*:*:* | ||
8.1r1.0CPE matchmatch criteria | cpe:2.3:a:pulsesecure:pulse_connect_secure:8.1r1.0:*:*:*:*:*:*:* | ||
8.1rxCPE matchmatch criteria | cpe:2.3:a:pulsesecure:pulse_connect_secure:8.1rx:*:*:*:*:*:*:* | ||
8.3rxCPE matchmatch criteria | cpe:2.3:a:pulsesecure:pulse_connect_secure:8.3rx:*:*:*:*:*:*:* | ||
5.2r1.0CPE matchmatch criteria | cpe:2.3:a:pulsesecure:pulse_policy_secure:5.2r1.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.