Patch bypass flaw in Pulse Secure VPNs can lead to total compromise (CVE-2021-22937)
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2020-8260 | Authenticated RCE in Ivanti Pulse Connect Secure admin web interface (pre-9.1R9) Ivanti Pulse Connect Secure versions before 9.1R9 contain a vulnerability (mapped to CWE-434) in the administrative web interface in which compressed uploads are handled with uncontrolled gzip extraction. An authenticated attacker with high-privilege (admin-level) access to that interface can send a crafted gzip-compressed file, triggering arbitrary code execution on the appliance with high impact to confidentiality, integrity, and availability (CVSS 3.1: 7.2, AV:N/PR:H). Successful exploitation yields arbitrary code execution on the VPN appliance itself, effectively enabling full compromise of the gateway that terminates the organization's VPN sessions. Any organization running Pulse Connect Secure on a release prior to 9.1R9 is affected, making the typical target an enterprise or government SSL VPN appliance accessible to anyone holding admin credentials. Exploitation is in the wild: the flaw is in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03), carries a 96.5% EPSS exploitation probability (100th percentile), and a public proof of concept is available. Do: Upgrade Pulse Connect Secure to 9.1R9 or later per the vendor's instructions; given the related patch-bypass flaw CVE-2021-22937 and the 'new urgent update' headlines, ensure the most recent available 9.1R release is applied rather than relying solely on the original 9.1R9 fix. Restrict the admin web interface to trusted management networks and review administrative accounts. Because the flaw is on CISA's KEV list and CISA has published malware analysis reports for Pulse Secure-targeted samples, hunt patched and unpatched devices for signs of compromise (e.g., web shells or implants). | 7.2 | 96% | KEV PoC |
| mass≈10^5 devices: a six-figure installed base of Pulse Connect Secure appliances, with tens of thousands internet-exposed in public scans at the time of the 2021… | |
| CVE-2021-22937 | A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator to perform a file write via a maliciously crafted archive uploa A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator to perform a file write via a maliciously crafted archive uploaded in the administrator web interface. NVD description · AI analysis pending | 7.2 | 8% |
| — |
Full article415 words · extracted from helpnetsecurity.com · click to collapse
The patch for a vulnerability (CVE-2020-8260) in Pulse Connect Secure VPN devices that attackers have been exploiting in the wild can be bypassed, security researcher Rich Warren has found. This new patch bypass vulnerability that could lead to remote code execution has been assigned a separate identification number (CVE-2021-22937) and has been fixed by Ivanti Pulse Secure on Monday (along with several other bugs).

While Warren hasn’t released a usable PoC, he has explained how the CVE-2020-8260 patch can be bypassed by simply changing a parameter variable in the original exploit. Such a simple change can be easily reproduced by attackers.
About CVE-2021-22937
CVE-2021-22937 is an uncontrolled archive extraction vulnerability that allows an attacker to overwrite arbitrary files.
“Successful exploitation of this issue results in Remote Code Execution on the underlying Operating System with root privileges. An attacker with such access will be able to circumvent any restrictions enforced via the web application, as well as remount the filesystem, allowing them to create a persistent backdoor, extract and decrypt credentials, compromise VPN clients, or pivot into the internal network,” Warren explained.
Ivanti Pulse Secure noted on Monday that, to their knowledge, none of the CVEs they fixed in the latest version of PCS (9.1R12) are under active exploitation. Nevertheless, they urge enterprise admins to upgrade their installations as soon as possible.
“In addition to addressing the CVEs, PCS version 9.1R12 includes enhanced features such as the incorporation of our Pulse Security Integrity Checker Tool directly into the product to create a seamless, more secure customer experience. This built-in feature eliminates the need for scheduled downtime to run an integrity check,” the company added.
UPDATE (August 7, 2021, 04:40 a.m. PT):
“A rigorous code review is just one of the steps we are taking to further bolster our security and protect our customers. For instance, we are also further expanding our existing internal product security resources to ramp up the pace and intensity of testing on existing products as well as those of companies or systems that we integrate into Ivanti,” Daniel Spicer, VP, Security at Ivanti, commented.
“Security threats across the industry will unfortunately persist. We will continue to partner closely with customers, law enforcement, government agencies and others in the security industry to help identify, prevent and mitigate new and emerging threats and protect our customers. We are grateful to researchers who bring concerns to our attention and would direct any researchers or customers to our Responsible Disclosure Policy.”
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2021/08/06/cve-2021-22937/