ZeroHour

CVE-2021-22894

KEVlarge

Authenticated Buffer Overflow RCE in Ivanti Pulse Connect Secure Collaboration Suite

CISA: Ivanti Pulse Connect Secure Collaboration Suite Buffer Overflow Vulnerability

CVSS 3.1
8.8 high
EPSS
41%p99
Published
()
KEV added
AI analysis

CVE-2021-22894 is a buffer overflow in the Collaboration Suite (meeting room) functionality of Ivanti Pulse Connect Secure, classified under CWE-94 (improper control of code generation). A remote attacker who is already authenticated to the appliance can trigger the overflow by supplying a maliciously crafted meeting room, causing attacker-controlled code to run on the appliance. Successful exploitation yields code execution as the root user, giving the attacker full control of the VPN appliance at the operating-system level. Any organization running Pulse Connect Secure with the Collaboration Suite feature enabled is potentially affected; specific affected version ranges are not specified in the available data. The flaw is on CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03), confirming in-the-wild exploitation, with an elevated 41.3% EPSS probability of exploitation in the next 30 days and no public proof-of-concept known.

What to do: Apply Ivanti's supplied updates for Pulse Connect Secure per vendor instructions immediately, as the flaw is on CISA's KEV list with a required-action deadline. Restrict or disable the Collaboration/meeting feature if not needed, ensure it is not reachable without authentication, and review appliance and authentication logs for signs of exploitation (unexpected processes, files, or sessions running as root).

Affected
Ivanti Pulse Connect Secure (Collaboration Suite / meeting room feature)
Estimated exposure
large≈tens of thousands of internet-exposed Pulse Connect Secure appliances (public 2021 scans showed roughly 20,000–50,000 Pulse Secure VPN endpoints) — Based on public internet scan counts of Pulse Secure VPN appliances around 2021 showing tens of thousands of exposed devices, further bounded by the fact that exploitation requires valid authenticated access to the meeting-room feature.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A buffer overflow vulnerability exists in Pulse Connect Secure before 9.1R11.4 allows a remote authenticated attacker to execute arbitrary code as the root user via maliciously crafted meeting room.

CISA Known Exploited Vulnerability
Affected
Ivanti Pulse Connect Secure
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
ivanti
Products
connect secure
Weakness
CWE-94, CWE-119
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news