CVE-2021-22899
KEVlarge1Authenticated Command Injection RCE in Ivanti Pulse Connect Secure
CISA: Ivanti Pulse Connect Secure Command Injection Vulnerability
Ivanti Pulse Connect Secure contains a command injection vulnerability (CWE-77) that allows a remote authenticated user to execute arbitrary operating-system commands on the appliance by abusing Windows File Resource Profiles. An attacker with valid credentials can turn this into full remote code execution on the VPN gateway, which typically serves as a gateway into the corporate network behind it. Any organization operating a Pulse Connect Secure remote-access appliance is in scope. Exploitation is confirmed: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03 with a required action to apply vendor updates, and EPSS assigns a high 22.9% probability of exploitation within 30 days (98th percentile). No public proof-of-concept is known, and whether ransomware groups use it is unconfirmed.
What to do: Apply vendor updates immediately per Ivanti's instructions, as required by the CISA KEV catalog. Because exploitation requires authentication, audit and restrict accounts on the appliance, review whether Windows File Resource Profiles are in use, and hunt for indicators of compromise on any gateway that was internet-exposed. Check Ivanti's guidance for the current supported release or migration path, since this appliance line has a designated successor product.
| Ivanti Pulse Connect Secure | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A command injection vulnerability exists in Pulse Connect Secure before 9.1R11.4 allows a remote authenticated attacker to perform remote code execution via Windows Resource Profiles Feature
- Affected
- Ivanti Pulse Connect Secure
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- ivanti
- Products
- connect secure
- Weakness
- CWE-77
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H