Junglewise Threat Intelligence

CVE-2021-22899: Ivanti Pulse Connect Secure Command Injection Vulnerability

CVE-2021-22899 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2021-11-03

Vendors: Ivanti.

Executive brief

A command injection vulnerability in Ivanti Pulse Connect Secure (formerly Pulse Secure) allows a remote authenticated attacker to execute arbitrary code via the Windows File Resource Profiles feature. This vulnerability has been observed being exploited in the wild.

Affected products

  • Ivanti Pulse Connect Secure before 9.1R11.4

Timeline

  • 2021-11-03: disclosed
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog