peter bassill · operator
$ cve CVE-2021-22893 JSON

CVE-2021-22893 KEV

10.0
CRITICAL · CVSS 3.1 · EPSS 47.2% (pctl 99)

Patch first

On CISA KEV — known exploited in the wild, due 2022-05-03.

Description

Pulse Connect Secure 9.0R3/9.1R1 and higher is vulnerable to an authentication bypass vulnerability exposed by the Windows File Share Browser and Pulse Secure Collaboration features of Pulse Connect Secure that can allow an unauthenticated user to perform remote arbitrary code execution on the Pulse Connect Secure gateway. This vulnerability has been exploited in the wild.

Scoring

CVSS10.0 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS47.17% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-287
On CISA KEVyes — remediate by 2022-05-03
Public exploitnone known
Published2021-04-23
Last modified2026-08-12

CISA KEV

NameIvanti Pulse Connect Secure Use-After-Free Vulnerability
Added2021-11-03
Due2022-05-03
Vendor / productIvanti / Pulse Connect Secure
Ransomware useknown

Affected (1)

VendorProduct
ivanticonnect secure

References

→ the Explorer  ·  watch your stack  ·  NVD