CVE-2020-8240
Estado: ModificadaAlta (7.8)—
A vulnerability in the Pulse Secure Desktop Client < 9.1R9 allows a restricted user on an endpoint machine can use system-level privileges if the Embedded Browser is configured with Credential Provider. This vulnerability only affects Windows PDC if the Embedded Browser is configured with the Credential Provider.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 7.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.33%
- Percentil entre todas las CVEs puntuadas: 23
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- NVD-CWE-noinfo
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2020-8240",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 6.9,
"accessVector": "LOCAL",
"vectorString": "AV:L/AC:M/Au:N/C:C/I:C/A:C",
"authentication": "NONE",
"integrityImpact": "COMPLETE",
"accessComplexity": "MEDIUM",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 3.4,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.8,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "support@hackerone.com",
"affectedData": [
{
"vendor": "n/a",
"product": "Pulse Secure Desktop Client",
"versions": [
{
"status": "affected",
"version": "9.1R9"
}
]
}
]
}
],
"published": "2020-10-28T13:15:12.387",
"references": [
{
"url": "https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44601",
"tags": [
"Vendor Advisory"
],
"source": "support@hackerone.com"
},
{
"url": "https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44601",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-noinfo"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability in the Pulse Secure Desktop Client < 9.1R9 allows a restricted user on an endpoint machine can use system-level privileges if the Embedded Browser is configured with Credential Provider. This vulnerability only affects Windows PDC if the Embedded Browser is configured with the Credential Provider."
},
{
"lang": "es",
"value": "Una vulnerabilidad en Pulse Secure Desktop Client versiones anteriores a 9.1R9, permite que un usuario restringido en una máquina endpoint pueda usar privilegios de nivel system si el Embedded Browser está configurado con Credential Provider. Esta vulnerabilidad solo afecta Windows PDC si el Embedded Browser está configurado con el Credential Provider"
}
],
"lastModified": "2026-06-17T03:26:06.867",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:pulsesecure:pulse_secure_desktop_client:*:*:*:*:*:windows:*:*",
"vulnerable": true,
"matchCriteriaId": "F3BBCA2A-A964-4B88-84D2-09199D7830D2",
"versionEndExcluding": "9.1"
},
{
"criteria": "cpe:2.3:a:pulsesecure:pulse_secure_desktop_client:9.1:r1:*:*:*:windows:*:*",
"vulnerable": true,
"matchCriteriaId": "5D8D50A3-4BCA-424C-80A6-FB748505E322"
},
{
"criteria": "cpe:2.3:a:pulsesecure:pulse_secure_desktop_client:9.1:r2:*:*:*:windows:*:*",
"vulnerable": true,
"matchCriteriaId": "4582A0E1-A8CE-41F1-B66B-093B6A6B0C5E"
},
{
"criteria": "cpe:2.3:a:pulsesecure:pulse_secure_desktop_client:9.1:r3:*:*:*:windows:*:*",
"vulnerable": true,
"matchCriteriaId": "E752E4C2-30CB-46D1-A785-49EDF2A15248"
},
{
"criteria": "cpe:2.3:a:pulsesecure:pulse_secure_desktop_client:9.1:r3.1:*:*:*:windows:*:*",
"vulnerable": true,
"matchCriteriaId": "75017203-FA52-4C5D-9B9C-E38F26852BB2"
},
{
"criteria": "cpe:2.3:a:pulsesecure:pulse_secure_desktop_client:9.1:r4:*:*:*:windows:*:*",
"vulnerable": true,
"matchCriteriaId": "C6460E3E-758A-41AC-A1A3-7288B5030C0F"
},
{
"criteria": "cpe:2.3:a:pulsesecure:pulse_secure_desktop_client:9.1:r4.1:*:*:*:windows:*:*",
"vulnerable": true,
"matchCriteriaId": "D16AD2E8-9C7D-4EA2-8AF1-881546E97D75"
},
{
"criteria": "cpe:2.3:a:pulsesecure:pulse_secure_desktop_client:9.1:r4.2:*:*:*:windows:*:*",
"vulnerable": true,
"matchCriteriaId": "FFB49374-0F24-41BA-BC44-51DC22D27B0B"
},
{
"criteria": "cpe:2.3:a:pulsesecure:pulse_secure_desktop_client:9.1:r5:*:*:*:windows:*:*",
"vulnerable": true,
"matchCriteriaId": "3996F908-D6EE-461B-8A2B-BF2FD94BB776"
},
{
"criteria": "cpe:2.3:a:pulsesecure:pulse_secure_desktop_client:9.1:r6:*:*:*:windows:*:*",
"vulnerable": true,
"matchCriteriaId": "F51DF92D-EEEC-4F2D-902C-6084201CAF05"
},
{
"criteria": "cpe:2.3:a:pulsesecure:pulse_secure_desktop_client:9.1:r7:*:*:*:windows:*:*",
"vulnerable": true,
"matchCriteriaId": "A502DBE4-F14E-4115-8AFE-12D47AEAFEF4"
},
{
"criteria": "cpe:2.3:a:pulsesecure:pulse_secure_desktop_client:9.1:r7.1:*:*:*:windows:*:*",
"vulnerable": true,
"matchCriteriaId": "EC134B99-2DDE-43F1-9808-A4AC4FDD943E"
},
{
"criteria": "cpe:2.3:a:pulsesecure:pulse_secure_desktop_client:9.1:r8:*:*:*:windows:*:*",
"vulnerable": true,
"matchCriteriaId": "A34AEAC3-082E-4EA3-B46B-782F11053F15"
},
{
"criteria": "cpe:2.3:a:pulsesecure:pulse_secure_desktop_client:9.1:r8.2:*:*:*:windows:*:*",
"vulnerable": true,
"matchCriteriaId": "32465036-9876-4AAD-86A0-C5503C0C55F4"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "support@hackerone.com"
}