SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2021-22893

Ivanti Pulse Connect Secure Use-After-Free Vulnerability

KEVCRITICAL 10.0EPSS 47.2%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 3 May 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

Pulse Connect Secure 9.0R3/9.1R1 and higher is vulnerable to an authentication bypass vulnerability exposed by the Windows File Share Browser and Pulse Secure Collaboration features of Pulse Connect Secure that can allow an unauthenticated user to perform remote arbitrary code execution on the Pulse Connect Secure gateway. This vulnerability has been exploited in the wild.

CVSS 3.1
10.0 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS
47.17% probability · 99th percentile
CISA KEV
Listed 3 November 2021 · due 3 May 2022 · used in ransomware campaigns
Weakness
CWE-287, CWE-416
Affected
ivanti/connect secure
Source
support@hackerone.com

CISA notes

Apply updates per vendor instructions. Reference CISA's ED 21-03 (https://www.cisa.gov/news-events/directives/ed-21-03-mitigate-pulse-connect-secure-product-vulnerabilities) for further guidance and requirements. Note: The due date for addressing this vulnerability aligns with the requirements outlined in ED 21-03. https://nvd.nist.gov/vuln/detail/CVE-2021-22893

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.