ZeroHour

CVE-2021-22900

KEVlarge

Authenticated Arbitrary File Upload in Ivanti Pulse Connect Secure (CVE-2021-22900)

CISA: Ivanti Pulse Connect Secure Unrestricted File Upload Vulnerability

CVSS 3.1
7.2 high
EPSS
14%p96
Published
()
KEV added
AI analysis

CVE-2021-22900 is an unrestricted file upload vulnerability in Ivanti Pulse Connect Secure (PCS) that affects versions before 9.1R11.4. It is triggered when an authenticated administrator uploads a maliciously crafted archive through the appliance's administrator web interface, allowing a file write without proper validation. An attacker holding (or who has compromised) administrator credentials can achieve a high-impact file write, classified under code injection (CWE-94), with high confidentiality, integrity and availability impact per the 7.2 CVSS score. Any organization running a Pulse Connect Secure appliance below 9.1R11.4 is affected, and because these are internet-facing enterprise VPN gateways, potentially exposed admin interfaces and appliance compromise are the main risks. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2021-11-03, confirming exploitation in the wild; no public PoC is known, ransomware use is unknown, and EPSS estimates a ~14% probability of exploitation within 30 days (96th percentile).

What to do: Upgrade Pulse Connect Secure to 9.1R11.4 or later per vendor instructions, as required by the CISA KEV listing. Because exploitation requires authenticated administrator access, restrict the admin web interface to trusted management networks, review administrator accounts and sessions for compromise, and inspect appliances for unexpected or modified files. Monitor for follow-on vendor guidance on appliance integrity checks.

Affected
Ivanti / Pulse Secure Pulse Connect Secureall versions before 9.1R11.4 (fixed in 9.1R11.4)
Ivanti / Pulse Secure Connect Secure (CPE product naming)all versions before 9.1R11.4 (fixed in 9.1R11.4)
Estimated exposure
largetens of thousands of internet-exposed Pulse Connect Secure appliances (est. 10k-100k systems) — Pulse Connect Secure was a widely deployed enterprise VPN gateway typically placed on the public internet, and internet-wide scans and vendor-reported install base around 2021 indicated an exposed population on the order of tens of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability allowed multiple unrestricted uploads in Pulse Connect Secure before 9.1R11.4 that could lead to an authenticated administrator to perform a file write via a maliciously crafted archive upload in the administrator web interface.

CISA Known Exploited Vulnerability
Affected
Ivanti Pulse Connect Secure
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
ivantipulsesecure
Products
connect secure, pulse connect secure
Weakness
CWE-94, CWE-669
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news