HIGH

CVE-2021-22894

Ivanti Connect Secure 2021-05-27 CVSS v3.1
CVSS
8.8
KEV

Description

A buffer overflow vulnerability exists in Pulse Connect Secure before 9.1R11.4 allows a remote authenticated attacker to execute arbitrary code as the root user via maliciously crafted meeting room.

Summary dbcve.org

A buffer overflow vulnerability in Pulse Connect Secure versions before 9.1R11.4 allows an authenticated remote attacker to execute arbitrary code with root privileges by using a maliciously crafted meeting room. This is a critical RCE vulnerability requiring authentication but achieving maximum-privilege (root) code execution.

Mitigation

Upgrade Pulse Connect Secure to version 9.1R11.4 or later. Given the CVSS 8.8 score and root-level code execution capability, this upgrade should be prioritized and performed in a controlled manner with backups and rollback capability.

Weakness (CWE)

CWE-94 Code Injection
CWE-119 Memory Buffer Bounds Error

EPSS Score

41.28%
Probability of exploitation in next 30 days
98.6th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE