HIGH
CVE-2021-22900
CVSS
7.2
KEV
Description
A vulnerability allowed multiple unrestricted uploads in Pulse Connect Secure before 9.1R11.4 that could lead to an authenticated administrator to perform a file write via a maliciously crafted archive upload in the administrator web interface.
Summary dbcve.org
A vulnerability in Pulse Connect Secure before version 9.1R11.4 allowed authenticated administrators to write arbitrary files via uploading maliciously crafted archive files through the administrator web interface, representing an unrestricted file upload flaw.
Mitigation
Upgrade Pulse Connect Secure to version 9.1R11.4 or later to remediate the file write vulnerability.
Weakness (CWE)
CWE-94
Code Injection
CWE-669
EPSS Score
14.15%
Probability of exploitation in next 30 days
96.4th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.