← Back

CVE-2021-22893

nvd nist
Published: Apr 23, 2021Modified: Dec 18, 2025CISA KEV

JSON object

Loading...
10.0
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 6.0
Source: NVD

Description

Pulse Connect Secure 9.0R3/9.1R1 and higher is vulnerable to an authentication bypass vulnerability exposed by the Windows File Share Browser and Pulse Secure Collaboration features of Pulse Connect Secure that can allow an unauthenticated user to perform remote arbitrary code execution on the Pulse Connect Secure gateway. This vulnerability has been exploited in the wild.

Affected (36)

1 product
Connect Secure
Configuration A
36 vulnerable
Vulnerable SoftwareAffected Versions
Ivanti
Version 9.0
Version 9.0 r1
Version 9.0 r2.1
Version 9.0 r2
Version 9.0 r3.1
Version 9.0 r3.2
Version 9.0 r3.3
Version 9.0 r3.5
Version 9.0 r3
Version 9.0 r4.1
Version 9.0 r4
Version 9.0 r5.0
Version 9.0 r6.0
Version 9.1
Version 9.1 r10.0
Version 9.1 r10.2
Version 9.1 r11.0
Version 9.1 r11.1
Version 9.1 r11.3
Version 9.1 r1
Version 9.1 r2
Version 9.1 r3
Version 9.1 r4.1
Version 9.1 r4.2
Version 9.1 r4.3
Version 9.1 r4
Version 9.1 r5
Version 9.1 r6
Version 9.1 r7
Version 9.1 r8.1
Version 9.1 r8.2
Version 9.1 r8.4
Version 9.1 r8
Version 9.1 r9.1
Version 9.1 r9.2
Version 9.1 r9

References (10)

Source: support@hackerone.com
Vendor Advisory
Source: support@hackerone.com
Third Party AdvisoryUS Government Resource
Source: support@hackerone.com
Broken LinkVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
US Government Resource
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
US Government Resource

Timeline

No history available yet.