CVE-2021-22894

CVE Published 2021-05-27
Related CWE(s) CWE-94: Improper Control of Generation of Code ('Code Injection'), CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
Related Vendor(s) pulsesecure, ivanti
Related Product(s) connect_secure, pulse_connect_secure
Exploitation Reported (CISA KEV) 2021-11-03
CVSS 3 Base Score 8.8 (HIGH)
CVSS 3 Attack Complexity LOW
CVSS 3 Attack Vector NETWORK

A buffer overflow vulnerability exists in Pulse Connect Secure before 9.1R11.4 allows a remote authenticated attacker to execute arbitrary code as the root user via maliciously crafted meeting room.

Cyber Threat Graph Context

Explore how this CVE relates to the wider threat graph

Associated CAPEC Patterns

References