CVE-2021-22900
Ivanti Pulse Connect Secure Unrestricted File Upload Vulnerability
A vulnerability allowed multiple unrestricted uploads in Pulse Connect Secure before 9.1R11.4 that could lead to an authenticated administrator to perform a file write via a maliciously crafted archive upload in the administrator web interface.
HIGH · CVSS 7.2
⚠ CISA KEV
EPSS 0.0098
Act now
- Listed on CISA KEV (known exploited in the wild)
- SSVC exploitation status: active
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0