Arbitrary file upload in Ivanti Connect Secure (formerly Pulse Connect Secure) - CVE-2021-22937
Published: August 5, 2021 / Updated: August 27, 2021
Ivanti Connect Secure (formerly Pulse Connect Secure)
Ivanti
Description
The vulnerability allows a remote user to compromise vulnerable system.
The vulnerability exists due to insufficient validation of file during file upload within the administrative interface. A remote privileged user can upload a malicious archive and execute it on the server.
Note, the vulnerability is being actively exploited in the wild as of August 2021.