CVE-2021-22900
KEVlargeAuthenticated Arbitrary File Upload in Ivanti Pulse Connect Secure (CVE-2021-22900)
CISA: Ivanti Pulse Connect Secure Unrestricted File Upload Vulnerability
CVE-2021-22900 is an unrestricted file upload vulnerability in Ivanti Pulse Connect Secure (PCS) that affects versions before 9.1R11.4. It is triggered when an authenticated administrator uploads a maliciously crafted archive through the appliance's administrator web interface, allowing a file write without proper validation. An attacker holding (or who has compromised) administrator credentials can achieve a high-impact file write, classified under code injection (CWE-94), with high confidentiality, integrity and availability impact per the 7.2 CVSS score. Any organization running a Pulse Connect Secure appliance below 9.1R11.4 is affected, and because these are internet-facing enterprise VPN gateways, potentially exposed admin interfaces and appliance compromise are the main risks. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2021-11-03, confirming exploitation in the wild; no public PoC is known, ransomware use is unknown, and EPSS estimates a ~14% probability of exploitation within 30 days (96th percentile).
What to do: Upgrade Pulse Connect Secure to 9.1R11.4 or later per vendor instructions, as required by the CISA KEV listing. Because exploitation requires authenticated administrator access, restrict the admin web interface to trusted management networks, review administrator accounts and sessions for compromise, and inspect appliances for unexpected or modified files. Monitor for follow-on vendor guidance on appliance integrity checks.
| Ivanti / Pulse Secure Pulse Connect Secure | all versions before 9.1R11.4 (fixed in 9.1R11.4) |
| Ivanti / Pulse Secure Connect Secure (CPE product naming) | all versions before 9.1R11.4 (fixed in 9.1R11.4) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability allowed multiple unrestricted uploads in Pulse Connect Secure before 9.1R11.4 that could lead to an authenticated administrator to perform a file write via a maliciously crafted archive upload in the administrator web interface.
- Affected
- Ivanti Pulse Connect Secure
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- ivantipulsesecure
- Products
- connect secure, pulse connect secure
- Weakness
- CWE-94, CWE-669
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H