CVE-2021-22894
KEVlargeAuthenticated Buffer Overflow RCE in Ivanti Pulse Connect Secure Collaboration Suite
CISA: Ivanti Pulse Connect Secure Collaboration Suite Buffer Overflow Vulnerability
CVE-2021-22894 is a buffer overflow in the Collaboration Suite (meeting room) functionality of Ivanti Pulse Connect Secure, classified under CWE-94 (improper control of code generation). A remote attacker who is already authenticated to the appliance can trigger the overflow by supplying a maliciously crafted meeting room, causing attacker-controlled code to run on the appliance. Successful exploitation yields code execution as the root user, giving the attacker full control of the VPN appliance at the operating-system level. Any organization running Pulse Connect Secure with the Collaboration Suite feature enabled is potentially affected; specific affected version ranges are not specified in the available data. The flaw is on CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03), confirming in-the-wild exploitation, with an elevated 41.3% EPSS probability of exploitation in the next 30 days and no public proof-of-concept known.
What to do: Apply Ivanti's supplied updates for Pulse Connect Secure per vendor instructions immediately, as the flaw is on CISA's KEV list with a required-action deadline. Restrict or disable the Collaboration/meeting feature if not needed, ensure it is not reachable without authentication, and review appliance and authentication logs for signs of exploitation (unexpected processes, files, or sessions running as root).
| Ivanti Pulse Connect Secure (Collaboration Suite / meeting room feature) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A buffer overflow vulnerability exists in Pulse Connect Secure before 9.1R11.4 allows a remote authenticated attacker to execute arbitrary code as the root user via maliciously crafted meeting room.
- Affected
- Ivanti Pulse Connect Secure
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- ivanti
- Products
- connect secure
- Weakness
- CWE-94, CWE-119
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H