Executive brief
A vulnerability in the Ivanti Pulse Connect Secure admin web interface allows an authenticated attacker to execute arbitrary code. The flaw stems from uncontrolled gzip extraction during file processing.
Affected products
- Ivanti Pulse Connect Secure < 9.1R9
Timeline
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2021-11-03: disclosed