HIGH

CVE-2021-22900

Ivanti Connect Secure 2021-05-27 CVSS v3.1
CVSS
7.2
KEV

Description

A vulnerability allowed multiple unrestricted uploads in Pulse Connect Secure before 9.1R11.4 that could lead to an authenticated administrator to perform a file write via a maliciously crafted archive upload in the administrator web interface.

Summary dbcve.org

A vulnerability in Pulse Connect Secure before version 9.1R11.4 allowed authenticated administrators to write arbitrary files via uploading maliciously crafted archive files through the administrator web interface, representing an unrestricted file upload flaw.

Mitigation

Upgrade Pulse Connect Secure to version 9.1R11.4 or later to remediate the file write vulnerability.

Weakness (CWE)

CWE-94 Code Injection
CWE-669

EPSS Score

14.15%
Probability of exploitation in next 30 days
96.4th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE