{"id":"CVE-2020-8260","aliases":[],"url":"https://o3.security/vulnerability/CVE-2020-8260","summary":"A vulnerability in the Pulse Connect Secure < 9.1R9 admin web interface could allow an authenticated attacker to perform an arbitrary code execution using uncontrolled gzip extraction.","details":"A vulnerability in the Pulse Connect Secure < 9.1R9 admin web interface could allow an authenticated attacker to perform an arbitrary code execution using uncontrolled gzip extraction.","published":"2020-10-28T12:47:13.000Z","modified":"2025-10-21T23:35:34.332Z","cvss":{"score":7.2,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"},"epss":{"score":0.9648,"percentile":0.99879,"asOf":"2026-09-05"},"cisaKev":null,"exploitsKnown":3,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44601"},{"type":"WEB","url":"http://packetstormsecurity.com/files/160619/Pulse-Secure-VPN-Remote-Code-Execution.html"},{"type":"WEB","url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-8260"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2025-10-21T23:35:34.332Z"}}