Vulnerability Description
Pulse Secure Desktop Client 9.0Rx before 9.0R5 and 9.1Rx before 9.1R4 on Windows reveals users' passwords if Save Settings is enabled.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Pulsesecure | Pulse Secure Desktop | 9.0r1.0 |
| Microsoft | Windows | - |
Related Weaknesses (CWE)
References
- https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44601Vendor Advisory
- https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44601Vendor Advisory
FAQ
What is CVE-2020-8956?
CVE-2020-8956 is a vulnerability with a CVSS score of 3.3 (LOW). Pulse Secure Desktop Client 9.0Rx before 9.0R5 and 9.1Rx before 9.1R4 on Windows reveals users' passwords if Save Settings is enabled.
How severe is CVE-2020-8956?
CVE-2020-8956 has been rated LOW with a CVSS base score of 3.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-8956?
Check the references section above for vendor advisories and patch information. Affected products include: Pulsesecure Pulse Secure Desktop, Microsoft Windows.