Junglewise Threat Intelligence

CVE-2021-22900: Ivanti Pulse Connect Secure Unrestricted File Upload Vulnerability

CVE-2021-22900 · Severity: critical · CVSS 7.2 · Exploited in the wild · Published 2021-11-03

Vendors: Ivanti.

Executive brief

Ivanti Pulse Connect Secure contains an unrestricted file upload vulnerability in the administrator web interface. An authenticated administrator can perform arbitrary file writes by uploading a maliciously crafted archive, potentially leading to code execution.

Affected products

  • Ivanti Pulse Connect Secure before 9.1R11.4

Timeline

  • 2021-11-03: disclosed
  • 2021-11-03: advisory: NVD publication date
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog