CVE-2018-20809 describes a denial-of-service vulnerability affecting Pulse Secure Pulse Connect Secure (PCS) versions 8.3RX prior to 8.3R5 and Pulse Policy Secure (PPS) versions 5.4RX prior to 5.4R5. An unauthenticated attacker can remotely crash the web server by sending a specially crafted message. With a CVSS v3 score of 7.5 (High), this vulnerability poses a significant availability risk as it can lead to service disruption. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
8.3CPE matchmatch criteria | cpe:2.3:a:ivanti:connect_secure:8.3:r1:*:*:*:*:*:* | ||
8.3CPE matchmatch criteria | cpe:2.3:a:ivanti:connect_secure:8.3:r2:*:*:*:*:*:* | ||
8.3CPE matchmatch criteria | cpe:2.3:a:ivanti:connect_secure:8.3:r2.1:*:*:*:*:*:* | ||
8.3CPE matchmatch criteria | cpe:2.3:a:ivanti:connect_secure:8.3:r3:*:*:*:*:*:* | ||
8.3CPE matchmatch criteria | cpe:2.3:a:ivanti:connect_secure:8.3:r4:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.