CVE-2021-22900
Ivanti Pulse Connect Secure Unrestricted File Upload Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
YesDecision
Descriptions
A vulnerability allowed multiple unrestricted uploads in Pulse Connect Secure before 9.1R11.4 that could lead to an authenticated administrator to perform a file write via a maliciously crafted archive upload in the administrator web interface.
Una vulnerabilidad permitió múltiples cargas sin restricciones en Pulse Connect Secure versiones anteriores a 9.1R11.4, que podrían conllevar a un administrador autenticado llevar a cabo una escritura de archivo por medio de una carga de archivo diseñada con fines maliciosos en la interfaz web del administrador
Ivanti Pulse Connect Secure contains an unrestricted file upload vulnerability that allows an authenticated administrator to perform a file write via a maliciously crafted archive upload in the administrator web interface.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-01-06 CVE Reserved
- 2021-04-23 KEV Due Date
- 2021-05-27 CVE Published
- 2021-11-03 Exploited in Wild
- 2024-04-18 EPSS Updated
- 2024-08-03 CVE Updated
- ---------- First Exploit
CWE
- CWE-94: Improper Control of Generation of Code ('Code Injection')
- CWE-669: Incorrect Resource Transfer Between Spheres
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44784/?kA23Z000000boUWSAY | 2024-02-27 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Ivanti Search vendor "Ivanti" | Connect Secure Search vendor "Ivanti" for product "Connect Secure" | 9.0 Search vendor "Ivanti" for product "Connect Secure" and version "9.0" | - |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Connect Secure Search vendor "Ivanti" for product "Connect Secure" | 9.0 Search vendor "Ivanti" for product "Connect Secure" and version "9.0" | r1 |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Connect Secure Search vendor "Ivanti" for product "Connect Secure" | 9.0 Search vendor "Ivanti" for product "Connect Secure" and version "9.0" | r1.0 |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Connect Secure Search vendor "Ivanti" for product "Connect Secure" | 9.0 Search vendor "Ivanti" for product "Connect Secure" and version "9.0" | r2 |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Connect Secure Search vendor "Ivanti" for product "Connect Secure" | 9.0 Search vendor "Ivanti" for product "Connect Secure" and version "9.0" | r2.0 |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Connect Secure Search vendor "Ivanti" for product "Connect Secure" | 9.0 Search vendor "Ivanti" for product "Connect Secure" and version "9.0" | r2.1 |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Connect Secure Search vendor "Ivanti" for product "Connect Secure" | 9.0 Search vendor "Ivanti" for product "Connect Secure" and version "9.0" | r3 |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Connect Secure Search vendor "Ivanti" for product "Connect Secure" | 9.0 Search vendor "Ivanti" for product "Connect Secure" and version "9.0" | r3.0 |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Connect Secure Search vendor "Ivanti" for product "Connect Secure" | 9.0 Search vendor "Ivanti" for product "Connect Secure" and version "9.0" | r3.1 |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Connect Secure Search vendor "Ivanti" for product "Connect Secure" | 9.0 Search vendor "Ivanti" for product "Connect Secure" and version "9.0" | r3.2 |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Connect Secure Search vendor "Ivanti" for product "Connect Secure" | 9.0 Search vendor "Ivanti" for product "Connect Secure" and version "9.0" | r3.3 |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Connect Secure Search vendor "Ivanti" for product "Connect Secure" | 9.0 Search vendor "Ivanti" for product "Connect Secure" and version "9.0" | r3.5 |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Connect Secure Search vendor "Ivanti" for product "Connect Secure" | 9.0 Search vendor "Ivanti" for product "Connect Secure" and version "9.0" | r4 |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Connect Secure Search vendor "Ivanti" for product "Connect Secure" | 9.0 Search vendor "Ivanti" for product "Connect Secure" and version "9.0" | r4.0 |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Connect Secure Search vendor "Ivanti" for product "Connect Secure" | 9.0 Search vendor "Ivanti" for product "Connect Secure" and version "9.0" | r4.1 |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Connect Secure Search vendor "Ivanti" for product "Connect Secure" | 9.0 Search vendor "Ivanti" for product "Connect Secure" and version "9.0" | r5.0 |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Connect Secure Search vendor "Ivanti" for product "Connect Secure" | 9.0 Search vendor "Ivanti" for product "Connect Secure" and version "9.0" | r6.0 |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Connect Secure Search vendor "Ivanti" for product "Connect Secure" | 9.1 Search vendor "Ivanti" for product "Connect Secure" and version "9.1" | - |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Connect Secure Search vendor "Ivanti" for product "Connect Secure" | 9.1 Search vendor "Ivanti" for product "Connect Secure" and version "9.1" | r1 |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Connect Secure Search vendor "Ivanti" for product "Connect Secure" | 9.1 Search vendor "Ivanti" for product "Connect Secure" and version "9.1" | r10.0 |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Connect Secure Search vendor "Ivanti" for product "Connect Secure" | 9.1 Search vendor "Ivanti" for product "Connect Secure" and version "9.1" | r10.2 |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Connect Secure Search vendor "Ivanti" for product "Connect Secure" | 9.1 Search vendor "Ivanti" for product "Connect Secure" and version "9.1" | r11.0 |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Connect Secure Search vendor "Ivanti" for product "Connect Secure" | 9.1 Search vendor "Ivanti" for product "Connect Secure" and version "9.1" | r11.1 |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Connect Secure Search vendor "Ivanti" for product "Connect Secure" | 9.1 Search vendor "Ivanti" for product "Connect Secure" and version "9.1" | r11.3 |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Connect Secure Search vendor "Ivanti" for product "Connect Secure" | 9.1 Search vendor "Ivanti" for product "Connect Secure" and version "9.1" | r2 |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Connect Secure Search vendor "Ivanti" for product "Connect Secure" | 9.1 Search vendor "Ivanti" for product "Connect Secure" and version "9.1" | r3 |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Connect Secure Search vendor "Ivanti" for product "Connect Secure" | 9.1 Search vendor "Ivanti" for product "Connect Secure" and version "9.1" | r4 |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Connect Secure Search vendor "Ivanti" for product "Connect Secure" | 9.1 Search vendor "Ivanti" for product "Connect Secure" and version "9.1" | r4.1 |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Connect Secure Search vendor "Ivanti" for product "Connect Secure" | 9.1 Search vendor "Ivanti" for product "Connect Secure" and version "9.1" | r4.2 |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Connect Secure Search vendor "Ivanti" for product "Connect Secure" | 9.1 Search vendor "Ivanti" for product "Connect Secure" and version "9.1" | r4.3 |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Connect Secure Search vendor "Ivanti" for product "Connect Secure" | 9.1 Search vendor "Ivanti" for product "Connect Secure" and version "9.1" | r5 |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Connect Secure Search vendor "Ivanti" for product "Connect Secure" | 9.1 Search vendor "Ivanti" for product "Connect Secure" and version "9.1" | r6 |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Connect Secure Search vendor "Ivanti" for product "Connect Secure" | 9.1 Search vendor "Ivanti" for product "Connect Secure" and version "9.1" | r7 |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Connect Secure Search vendor "Ivanti" for product "Connect Secure" | 9.1 Search vendor "Ivanti" for product "Connect Secure" and version "9.1" | r8 |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Connect Secure Search vendor "Ivanti" for product "Connect Secure" | 9.1 Search vendor "Ivanti" for product "Connect Secure" and version "9.1" | r8.1 |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Connect Secure Search vendor "Ivanti" for product "Connect Secure" | 9.1 Search vendor "Ivanti" for product "Connect Secure" and version "9.1" | r8.2 |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Connect Secure Search vendor "Ivanti" for product "Connect Secure" | 9.1 Search vendor "Ivanti" for product "Connect Secure" and version "9.1" | r8.4 |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Connect Secure Search vendor "Ivanti" for product "Connect Secure" | 9.1 Search vendor "Ivanti" for product "Connect Secure" and version "9.1" | r9 |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Connect Secure Search vendor "Ivanti" for product "Connect Secure" | 9.1 Search vendor "Ivanti" for product "Connect Secure" and version "9.1" | r9.1 |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Connect Secure Search vendor "Ivanti" for product "Connect Secure" | 9.1 Search vendor "Ivanti" for product "Connect Secure" and version "9.1" | r9.2 |
Affected
| ||||||
Pulsesecure Search vendor "Pulsesecure" | Pulse Connect Secure Search vendor "Pulsesecure" for product "Pulse Connect Secure" | <= 9.1 Search vendor "Pulsesecure" for product "Pulse Connect Secure" and version " <= 9.1" | - |
Affected
|