HIGH

CVE-2021-22899

Ivanti Connect Secure 2021-05-27 CVSS v3.1
CVSS
8.8
KEV

Description

A command injection vulnerability exists in Pulse Connect Secure before 9.1R11.4 allows a remote authenticated attacker to perform remote code execution via Windows Resource Profiles Feature

Summary dbcve.org

Command injection vulnerability in Pulse Connect Secure's Windows Resource Profiles feature allows authenticated remote attackers to execute arbitrary commands on the underlying system, leading to complete system compromise.

Mitigation

Upgrade Pulse Connect Secure to version 9.1R11.4 or later to remediate this vulnerability.

Weakness (CWE)

CWE-77 Command Injection

EPSS Score

22.92%
Probability of exploitation in next 30 days
97.7th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE