CVE-2020-15408: Pulse Secure Pulse Connect Secure
Medium severity, CVSS 4.6. EPSS: 0.8% chance of exploitation in the next 30 days.
An issue was discovered in Pulse Secure Pulse Connect Secure before 9.1R8. An authenticated attacker can access the admin page console via the end-user web interface because of a rewrite.
Affected products
- Pulse Secure Pulse Connect Secure: up to and including 9.1
- Pulse Secure Pulse Secure Desktop Client: version 9.1 only
Published 2020-07-28. Last modified 2026-06-17.