CVE-2021-22894
Description
A buffer overflow vulnerability exists in Pulse Connect Secure before 9.1R11.4 allows a remote authenticated attacker to execute arbitrary code as the root user via maliciously crafted meeting room.
Summary dbcve.org
A buffer overflow vulnerability in Pulse Connect Secure versions before 9.1R11.4 allows an authenticated remote attacker to execute arbitrary code with root privileges by using a maliciously crafted meeting room. This is a critical RCE vulnerability requiring authentication but achieving maximum-privilege (root) code execution.
Mitigation
Upgrade Pulse Connect Secure to version 9.1R11.4 or later. Given the CVSS 8.8 score and root-level code execution capability, this upgrade should be prioritized and performed in a controlled manner with backups and rollback capability.