Skip to content
COOEY

EXPOSURES › CVE-2021-22893

CVE-2021-22893

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2021-22893 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 ransomwarerceexploited-in-wildunpatched

Ivanti Pulse Connect Secure's use-after-free vulnerability allowed unauthenticated attackers to execute code remotely, and is actively being exploited in ransomware attacks.

A critical use-after-free vulnerability in Ivanti Pulse Connect Secure enables remote code execution without authentication, and is currently being exploited in the wild, often linked to ransomware. DIB organizations using this product face immediate exposure and potential compliance failures under CMMC/NIST 800-171, requiring urgent patching and incident response. Verify your environment’s status and apply Ivanti’s provided patches immediately.

Shame score — The vulnerability's ease of exploitation, remote access, and active ransomware association demonstrate significant negligence and pose a severe risk to DIB organizations.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Ivanti Pulse Connect Secure contains a use-after-free vulnerability that allow a remote, unauthenticated attacker to execute code via license services.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.60
Vulnerability allows remote code execution without authentication, representing a critical security failure.
cooey ↗ severe-fallout -0.60
Critical unauthenticated remote code execution flaw in license services.
"Ivanti Pulse Connect Secure contains a use-after-free vulnerability that allow a remote, unauthenticated attacker to execute code via license services."
AFFECTED FEDRAMP PRODUCTS · 2
PRODUCTSTATUS
Ivanti Neurons for ITSM (Formerly Service Manager)
Ivanti
Authorized
Ivanti Neurons for MDM (Formerly MobileIron)
Ivanti
Authorized