Executive brief
A code injection vulnerability in Pulse Connect Secure (now Ivanti Connect Secure) allows an authenticated administrator to execute arbitrary code by crafting a specific URI via the admin web interface. The vulnerability affects versions prior to 9.1R8 and has been observed being exploited in the wild.
Affected products
- Pulse Secure Pulse Connect Secure < 9.1R8
- Ivanti Connect Secure < 9.1R8
Timeline
- 2020-11-13: disclosed: Public blog post detailing the vulnerability published by GoSecure.
- 2022-03-07: kev added: Added to CISA's Known Exploited Vulnerabilities (KEV) catalog.