Threat Advisory: Pulse Secure Connect Coverage
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2019-11510 | Unauthenticated Arbitrary File Read in Ivanti Pulse Connect Secure VPN Ivanti Pulse Connect Secure, an enterprise SSL VPN appliance, contains an arbitrary file read vulnerability (CWE-22, path traversal) that requires no authentication. An unauthenticated remote attacker with network access to the appliance over HTTPS can send a specially crafted URI containing traversal sequences to read arbitrary files from the device. The attacker gains access to sensitive appliance files, potentially including configuration or credential material useful for further compromise, and CISA records known ransomware use of this flaw. Any organization running Pulse Connect Secure, especially gateways exposed to the internet for remote access, is affected. Exploitation is established: CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2021-11-03 with known ransomware use, EPSS assigns a 100% probability of exploitation in the next 30 days, and no public PoC is known. Do: Apply updates per Ivanti's instructions, the required action in the CISA KEV entry, prioritizing internet-facing Pulse Connect Secure gateways, and consult the vendor advisory for the applicable fixed release since no version range is provided here. Where patching is not immediate, restrict HTTPS access to the appliance and hunt for signs of exploitation (unexpected file reads, anomalous VPN logins or sessions, and follow-on ransomware activity), as CISA reports known ransomware use. | 10.0 | 100% | KEV ransomware PoC ×2 |
| largeTens of thousands of internet-exposed gateways (order of 10,000-100,000 systems; each typically serves hundreds of VPN users, so potentially millions of users) | |
| CVE-2020-8243 | Authenticated Arbitrary Code Execution via Template Upload in Ivanti Pulse Connect Secure CVE-2020-8243 is a code injection flaw (CWE-94) in the administrator web interface of Ivanti Pulse Connect Secure versions prior to 9.1R8.2. An authenticated attacker with administrative privileges can upload a custom template through the admin interface, which results in arbitrary code execution on the appliance. Successful exploitation gives the attacker full control over the VPN gateway, including access to network traffic, stored credentials, and a foothold for pivoting into the internal network. Any organization running an affected Pulse Connect Secure version is exposed, and administrators should note the flaw requires admin-level access, which lowers risk when the management interface is not reachable by untrusted users. The vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03) and carries a very high EPSS score of about 91%, indicating active or highly likely exploitation; Pulse Secure VPN appliances broadly were also the target of APT exploitation activity in 2021. Do: Upgrade Pulse Connect Secure to 9.1R8.2 or later per the vendor's instructions, as required by the CISA KEV listing. Restrict the admin web interface to trusted management networks and review appliances for suspicious custom templates, modified configurations, or added administrator accounts, since Pulse Secure devices have been a documented target of APT intrusion tooling. | 7.2 | 91% | KEV |
| largetens of thousands of internet-exposed Pulse Connect Secure appliances (~20,000–30,000+ in public scans), with far more deployed for internal/remote access | |
| CVE-2020-8260 | Authenticated RCE in Ivanti Pulse Connect Secure admin web interface (pre-9.1R9) Ivanti Pulse Connect Secure versions before 9.1R9 contain a vulnerability (mapped to CWE-434) in the administrative web interface in which compressed uploads are handled with uncontrolled gzip extraction. An authenticated attacker with high-privilege (admin-level) access to that interface can send a crafted gzip-compressed file, triggering arbitrary code execution on the appliance with high impact to confidentiality, integrity, and availability (CVSS 3.1: 7.2, AV:N/PR:H). Successful exploitation yields arbitrary code execution on the VPN appliance itself, effectively enabling full compromise of the gateway that terminates the organization's VPN sessions. Any organization running Pulse Connect Secure on a release prior to 9.1R9 is affected, making the typical target an enterprise or government SSL VPN appliance accessible to anyone holding admin credentials. Exploitation is in the wild: the flaw is in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03), carries a 96.5% EPSS exploitation probability (100th percentile), and a public proof of concept is available. Do: Upgrade Pulse Connect Secure to 9.1R9 or later per the vendor's instructions; given the related patch-bypass flaw CVE-2021-22937 and the 'new urgent update' headlines, ensure the most recent available 9.1R release is applied rather than relying solely on the original 9.1R9 fix. Restrict the admin web interface to trusted management networks and review administrative accounts. Because the flaw is on CISA's KEV list and CISA has published malware analysis reports for Pulse Secure-targeted samples, hunt patched and unpatched devices for signs of compromise (e.g., web shells or implants). | 7.2 | 96% | KEV PoC |
| mass≈10^5 devices: a six-figure installed base of Pulse Connect Secure appliances, with tens of thousands internet-exposed in public scans at the time of the 2021… | |
| CVE-2021-22893 | Use-After-Free RCE in Ivanti Pulse Connect Secure License Services Ivanti Pulse Connect Secure, a widely deployed SSL VPN appliance, contains a use-after-free vulnerability in its license services. A remote, unauthenticated attacker can trigger the flaw via the license services and gain arbitrary code execution on the appliance, which is a high-value target because it terminates VPN sessions for enterprise networks. Any organization running an affected Pulse Connect Secure release is potentially affected; the source data does not specify exact version ranges, so administrators should compare their release against Ivanti's advisory. Exploitation is confirmed in the wild: the flaw is on CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03) with known ransomware use, and its 47.2% EPSS score (99th percentile) indicates a high likelihood of exploitation within 30 days. Do: Apply the updates per Ivanti's instructions immediately, as CISA's required action specifies. Because exploited appliances have often retained persistent webshells/backdoors even after patching, also hunt for indicators of compromise (modified appliance files, unexpected processes or accounts) and follow Ivanti's remediation guidance rather than only installing the update. Until patched, restrict or closely monitor internet access to the appliance. | 10.0 | 47% | KEV ransomware |
| largetens of thousands of internet-exposed Pulse Connect Secure VPN appliances (order of magnitude ~10^4-10^5) |
Full article512 words · extracted from blog.talosintelligence.com · click to collapse
Thursday, April 22, 2021 09:50
Pulse Secure announced that a critical vulnerability (CVE-2021-22893) was discovered in their VPN service "Pulse Secure Connect" in a recent security advisory.
The advisory states that, "a vulnerability was discovered under Pulse Connect Secure (PCS). This includes an authentication by-pass vulnerability that can allow an unauthenticated user to perform remote arbitrary file execution on the Pulse Connect Secure gateway. This vulnerability has a critical CVSS score and poses a significant risk to your deployment."
The company released a blog post alongside this advisory disclosing that the vulnerability has been exploited in the wild. According to the blog post, several other previously known vulnerabilities were exploited during these incidents:
- CVE-2019-11510
- CVE-2020-8243
- CVE-2020-8260 The U.S. Cybersecurity and Infrastructure Security Agency also also released an alert warning of these vulnerabilities. In the alert, CISA notes that networks belonging to multiple government agencies, critical infrastructure entities and private sector organizations have been compromised going as far back as June 2020.
VPN vulnerabilities of this nature are exploited by a wide variety of threat actors, including ransomware groups and potentially state-sponsored actors. In one of our previous blog posts, we cover an advisory by the U.S. National Security Agency that outlines several vulnerabilities that the Russian Foreign Intelligence Services (SVR) exploited in the wild. One of the CVEs discussed in the advisory is CVE-2019-11510, which was also leveraged in the Pulse Connect attacks described above.
Mitigation
Pulse Connect has released a tool for checking the integrity of the PCS software. Cisco Talos also recommends updating to the most recent version of Pulse Connect Secure as soon as possible, as the previously known vulnerabilities (CVE-2019-11510, CVE-2020-8243, CVE-2020-8260) have been fixed in patches released by Pulse Secure. However, the most recent vulnerability, CVE-2021-22893, has not yet been patched, according to Pulse Secure. A patch is expected to be released in May.
The U.S. Department of Homeland Security has also released an Emergency Directive detailing the incident and required actions for mitigation.
While Cisco Talos is continually monitoring this threat as it develops and adding coverage as new information emerges, we strongly urge to employ the mitigation techniques provided by CISA and Pulse Connect.
The links to mitigations and advisories from this article are listed below:
- PCS Integrity Assurance Tool
- CVE-2021-22893 Pulse Connect Advisory
- CVE-2019-11510 Pulse Connect Advisory
- CVE-2020-8243 Pulse Connect Advisory
- CVE-2020-8260 Pulse Connect Advisory
- CISA Alert
- DHS Emergency Directive
Coverage
The following SNORTⓇ rules will detect exploitation attempts. Note that additional rules may be released at a future date and current rules are subject to change pending additional vulnerability information. For the most current rule information, please refer to your Firepower Management Center or Snort.org. Please note that some of these vulnerabilities exploit applications leveraging SSL. This means that users should enable SSL decryption in Cisco Secure Firewall and Snort to detect exploitation of these vulnerabilities. For some examples of this, see how it can be done to protect against exploits associated with Bluekeep and Hafnium.
Snort Rules: 51288, 51289, 51390, 57452-57459, and 57461-57468
Text extracted automatically; images, tables and formatting may be missing. Original: https://blog.talosintelligence.com/pulse-vpn-coverage/