CRITICAL

CVE-2021-22893

Ivanti Connect Secure 2021-04-23 CVSS v3.1
CVSS
10
KEV

Description

Pulse Connect Secure 9.0R3/9.1R1 and higher is vulnerable to an authentication bypass vulnerability exposed by the Windows File Share Browser and Pulse Secure Collaboration features of Pulse Connect Secure that can allow an unauthenticated user to perform remote arbitrary code execution on the Pulse Connect Secure gateway. This vulnerability has been exploited in the wild.

Summary dbcve.org

Pulse Connect Secure SSL VPN gateway versions 9.0R3 through 9.1R1 and higher contain an authentication bypass vulnerability in the Windows File Share Browser and Pulse Secure Collaboration features. This allows unauthenticated attackers to execute arbitrary code remotely on the VPN gateway, achieving complete system compromise. The vulnerability has been actively exploited in the wild.

Mitigation

Immediately patch to the vendor-supplied fixed version. Given the CVSS 10 severity and active exploitation, treat this as a critical incident: isolate the device if compromise is suspected, apply the patch urgently, and conduct a full forensic review.

Weakness (CWE)

CWE-287 Improper Authentication
CWE-416 Use After Free

EPSS Score

47.17%
Probability of exploitation in next 30 days
98.8th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE