Executive brief
A vulnerability in the Ivanti Pulse Connect Secure admin web interface allows an authenticated attacker with high privileges to upload a custom template. This can be leveraged to achieve arbitrary code execution on the underlying system.
Affected products
- Ivanti Pulse Connect Secure < 9.1R8.2
- Ivanti Pulse Policy Secure < 9.1R8.2
Timeline
- 2021-11-03: disclosed
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2021-11-03: advisory: NVD publication date