Arbitrary file upload in Ivanti Connect Secure (formerly Pulse Connect Secure) - CVE-2021-22937

 

Arbitrary file upload in Ivanti Connect Secure (formerly Pulse Connect Secure) - CVE-2021-22937

Published: August 5, 2021 / Updated: August 27, 2021


Vulnerability identifier: #VU55617
CSH Severity: Low
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-22937
CWE-ID: CWE-434
Exploitation vector: Remote access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a remote user to compromise vulnerable system.

The vulnerability exists due to insufficient validation of file during file upload within the administrative interface. A remote privileged user can upload a malicious archive and execute it on the server.

Note, the vulnerability is being actively exploited in the wild as of August 2021.


Affected software

Ivanti Connect Secure (formerly Pulse Connect Secure)

How to mitigate CVE-2021-22937

Install updates from vendor's website.

Ivanti Connect Secure (formerly Pulse Connect Secure) - update to 9.1R12

External References

Related Security Bulletins