CVE-2021-22900
CVE Published | 2021-05-27 |
---|---|
Related CWE(s) | CWE-669: Incorrect Resource Transfer Between Spheres, CWE-94: Improper Control of Generation of Code ('Code Injection') |
Related Vendor(s) | pulsesecure, ivanti |
Related Product(s) | connect_secure, pulse_connect_secure |
Exploitation Reported (CISA KEV) | 2021-11-03 |
CVSS 3 Base Score | 7.2 (HIGH) |
CVSS 3 Attack Complexity | LOW |
CVSS 3 Attack Vector | NETWORK |
A vulnerability allowed multiple unrestricted uploads in Pulse Connect Secure before 9.1R11.4 that could lead to an authenticated administrator to perform a file write via a maliciously crafted archive upload in the administrator web interface.
Cyber Threat Graph Context
Explore how this CVE relates to the wider threat graph