CVE-2021-22900

CVE Published 2021-05-27
Related CWE(s) CWE-669: Incorrect Resource Transfer Between Spheres, CWE-94: Improper Control of Generation of Code ('Code Injection')
Related Vendor(s) pulsesecure, ivanti
Related Product(s) connect_secure, pulse_connect_secure
Exploitation Reported (CISA KEV) 2021-11-03
CVSS 3 Base Score 7.2 (HIGH)
CVSS 3 Attack Complexity LOW
CVSS 3 Attack Vector NETWORK

A vulnerability allowed multiple unrestricted uploads in Pulse Connect Secure before 9.1R11.4 that could lead to an authenticated administrator to perform a file write via a maliciously crafted archive upload in the administrator web interface.

Cyber Threat Graph Context

Explore how this CVE relates to the wider threat graph

Associated CAPEC Patterns

References