HIGH
CVE-2021-22899
CVSS
8.8
KEV
Description
A command injection vulnerability exists in Pulse Connect Secure before 9.1R11.4 allows a remote authenticated attacker to perform remote code execution via Windows Resource Profiles Feature
Summary dbcve.org
Command injection vulnerability in Pulse Connect Secure's Windows Resource Profiles feature allows authenticated remote attackers to execute arbitrary commands on the underlying system, leading to complete system compromise.
Mitigation
Upgrade Pulse Connect Secure to version 9.1R11.4 or later to remediate this vulnerability.
Weakness (CWE)
CWE-77
Command Injection
EPSS Score
22.92%
Probability of exploitation in next 30 days
97.7th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.