CVE-2021-22894

CVE Published 2021-05-27
Related CWE(s) CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer, CWE-94: Improper Control of Generation of Code ('Code Injection')
Related Vendor(s) ivanti, pulsesecure
Related Product(s) pulse_connect_secure, connect_secure
Exploitation Reported (CISA KEV) 2021-11-03
CVSS 3 Base Score 8.8 (HIGH)
CVSS 3 Attack Complexity LOW
CVSS 3 Attack Vector NETWORK

A buffer overflow vulnerability exists in Pulse Connect Secure before 9.1R11.4 allows a remote authenticated attacker to execute arbitrary code as the root user via maliciously crafted meeting room.

Cyber Threat Graph Context

Explore how this CVE relates to the wider threat graph

Associated CAPEC Patterns

References