8.8

CVE-2021-22899

Warnung
A command injection vulnerability exists in Pulse Connect Secure before 9.1R11.4 allows a remote authenticated attacker to perform remote code execution via Windows Resource Profiles Feature
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ivanti ≫ Connect Secure Version 9.0 Update -
Ivanti ≫ Connect Secure Version 9.0 Update r1
Ivanti ≫ Connect Secure Version 9.0 Update r1.0
Ivanti ≫ Connect Secure Version 9.0 Update r2
Ivanti ≫ Connect Secure Version 9.0 Update r2.0
Ivanti ≫ Connect Secure Version 9.0 Update r2.1
Ivanti ≫ Connect Secure Version 9.0 Update r3
Ivanti ≫ Connect Secure Version 9.0 Update r3.0
Ivanti ≫ Connect Secure Version 9.0 Update r3.1
Ivanti ≫ Connect Secure Version 9.0 Update r3.2
Ivanti ≫ Connect Secure Version 9.0 Update r3.3
Ivanti ≫ Connect Secure Version 9.0 Update r3.5
Ivanti ≫ Connect Secure Version 9.0 Update r4
Ivanti ≫ Connect Secure Version 9.0 Update r4.0
Ivanti ≫ Connect Secure Version 9.0 Update r4.1
Ivanti ≫ Connect Secure Version 9.0 Update r5.0
Ivanti ≫ Connect Secure Version 9.0 Update r6.0
Ivanti ≫ Connect Secure Version 9.0 Update rx
Ivanti ≫ Connect Secure Version 9.1 Update -
Ivanti ≫ Connect Secure Version 9.1 Update r1
Ivanti ≫ Connect Secure Version 9.1 Update r10.0
Ivanti ≫ Connect Secure Version 9.1 Update r10.2
Ivanti ≫ Connect Secure Version 9.1 Update r11.0
Ivanti ≫ Connect Secure Version 9.1 Update r11.1
Ivanti ≫ Connect Secure Version 9.1 Update r11.3
Ivanti ≫ Connect Secure Version 9.1 Update r2
Ivanti ≫ Connect Secure Version 9.1 Update r3
Ivanti ≫ Connect Secure Version 9.1 Update r4
Ivanti ≫ Connect Secure Version 9.1 Update r4.1
Ivanti ≫ Connect Secure Version 9.1 Update r4.2
Ivanti ≫ Connect Secure Version 9.1 Update r4.3
Ivanti ≫ Connect Secure Version 9.1 Update r5
Ivanti ≫ Connect Secure Version 9.1 Update r6
Ivanti ≫ Connect Secure Version 9.1 Update r7
Ivanti ≫ Connect Secure Version 9.1 Update r8
Ivanti ≫ Connect Secure Version 9.1 Update r8.1
Ivanti ≫ Connect Secure Version 9.1 Update r8.2
Ivanti ≫ Connect Secure Version 9.1 Update r8.4
Ivanti ≫ Connect Secure Version 9.1 Update r9
Ivanti ≫ Connect Secure Version 9.1 Update r9.1
Ivanti ≫ Connect Secure Version 9.1 Update r9.2

03.11.2021: CISA Known Exploited Vulnerabilities (KEV) Catalog

Ivanti Pulse Connect Secure Command Injection Vulnerability

Schwachstelle

Ivanti Pulse Connect Secure contains a command injection vulnerability that allows remote authenticated users to perform remote code execution via Windows File Resource Profiles.

Beschreibung

Apply updates per vendor instructions.

Erforderliche Maßnahmen
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 22.92% 0.975
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
NIST 6.5 8 6.4
AV:N/AC:L/Au:S/C:P/I:P/A:P
CISA-ADP 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44784/?kA23Z000000boUWSAY
Vendor Advisory
Broken Link
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-22899
US Government Resource