CVE-2021-22893
Ivanti Pulse Connect Secure Use-After-Free Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 3 May 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
Pulse Connect Secure 9.0R3/9.1R1 and higher is vulnerable to an authentication bypass vulnerability exposed by the Windows File Share Browser and Pulse Secure Collaboration features of Pulse Connect Secure that can allow an unauthenticated user to perform remote arbitrary code execution on the Pulse Connect Secure gateway. This vulnerability has been exploited in the wild.
- CVSS 3.1
- 10.0 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- EPSS
- 47.17% probability · 99th percentile
- CISA KEV
- Listed 3 November 2021 · due 3 May 2022 · used in ransomware campaigns
- Weakness
- CWE-287, CWE-416
- Affected
- ivanti/connect secure
- Source
- support@hackerone.com
CISA notes
Apply updates per vendor instructions. Reference CISA's ED 21-03 (https://www.cisa.gov/news-events/directives/ed-21-03-mitigate-pulse-connect-secure-product-vulnerabilities) for further guidance and requirements. Note: The due date for addressing this vulnerability aligns with the requirements outlined in ED 21-03. https://nvd.nist.gov/vuln/detail/CVE-2021-22893
References
- https://blog.pulsesecure.net/pulse-connect-secure-security-update/Vendor Advisory
- https://kb.cert.org/vuls/id/213092Third Party Advisory, US Government Resource
- https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44784/Broken Link, Vendor Advisory
- https://www.fireeye.com/blog/threat-research/2021/04/suspected-apt-actors-leverage-bypass-techniques-pulse-secure-zero-day.htmlThird Party Advisory
- https://blog.pulsesecure.net/pulse-connect-secure-security-update/Vendor Advisory
- https://kb.cert.org/vuls/id/213092Third Party Advisory, US Government Resource
- https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44784/Broken Link, Vendor Advisory
- https://www.fireeye.com/blog/threat-research/2021/04/suspected-apt-actors-leverage-bypass-techniques-pulse-secure-zero-day.htmlThird Party Advisory
- https://www.kb.cert.org/vuls/id/213092US Government Resource
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-22893US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.