ZeroHour

CVE-2021-22899

KEVlarge1

Authenticated Command Injection RCE in Ivanti Pulse Connect Secure

CISA: Ivanti Pulse Connect Secure Command Injection Vulnerability

CVSS 3.1
8.8 high
EPSS
23%p98
Published
()
KEV added
AI analysis

Ivanti Pulse Connect Secure contains a command injection vulnerability (CWE-77) that allows a remote authenticated user to execute arbitrary operating-system commands on the appliance by abusing Windows File Resource Profiles. An attacker with valid credentials can turn this into full remote code execution on the VPN gateway, which typically serves as a gateway into the corporate network behind it. Any organization operating a Pulse Connect Secure remote-access appliance is in scope. Exploitation is confirmed: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03 with a required action to apply vendor updates, and EPSS assigns a high 22.9% probability of exploitation within 30 days (98th percentile). No public proof-of-concept is known, and whether ransomware groups use it is unconfirmed.

What to do: Apply vendor updates immediately per Ivanti's instructions, as required by the CISA KEV catalog. Because exploitation requires authentication, audit and restrict accounts on the appliance, review whether Windows File Resource Profiles are in use, and hunt for indicators of compromise on any gateway that was internet-exposed. Check Ivanti's guidance for the current supported release or migration path, since this appliance line has a designated successor product.

Affected
Ivanti Pulse Connect Secure
Estimated exposure
largetens of thousands of internet-exposed Pulse Connect Secure gateways (order of magnitude ~10k-75k appliances), each serving many remote users — Based on public internet-wide scan counts of Pulse Secure VPN endpoints around 2021 and the appliance's wide use as an enterprise remote-access gateway, so affected user counts run substantially higher than exposed device counts.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A command injection vulnerability exists in Pulse Connect Secure before 9.1R11.4 allows a remote authenticated attacker to perform remote code execution via Windows Resource Profiles Feature

CISA Known Exploited Vulnerability
Affected
Ivanti Pulse Connect Secure
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
ivanti
Products
connect secure
Weakness
CWE-77
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news