CVE-2021-22900 is a critical vulnerability affecting Ivanti/Pulse Secure Connect Secure before 9.1R11.4, allowing an authenticated administrator to upload malicious archives via the web interface, leading to arbitrary file writes. This vulnerability carries a high CVSS score of 7.2, indicating a network-based attack with low complexity, requiring high privileges, and resulting in complete compromise of confidentiality, integrity, and availability. Notably, it is listed in CISA's KEV catalog, confirming active exploitation in the wild, despite a lack of public exploit code, and has garnered significant community discussion and media attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
9.0CPE matchmatch criteria | cpe:2.3:a:ivanti:connect_secure:9.0:-:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:a:ivanti:connect_secure:9.0:r1:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:a:ivanti:connect_secure:9.0:r1.0:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:a:ivanti:connect_secure:9.0:r2:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:a:ivanti:connect_secure:9.0:r2.0:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.