Skip to content
COOEY

EXPOSURES › CVE-2021-22894

CVE-2021-22894

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2021-22894 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 78/100 rceexploited-in-wildunpatched

Ivanti Pulse Connect Secure suffered a buffer overflow allowing remote authenticated users to execute root code via malicious meeting rooms.

A buffer overflow in Ivanti Pulse Connect Secure lets authenticated attackers run arbitrary code as root through crafted meeting room data. DIBs must patch this immediately as it enables full system compromise and violates CMMC/NIST 800-171 controls around remote access and privileged access. Organizations should verify patch levels and restrict meeting room access to trusted sources.

Shame score — A remote code execution flaw in a widely deployed remote access product that allows root-level compromise via a common attack vector like meeting rooms.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Ivanti Pulse Connect Secure Collaboration Suite contains a buffer overflow vulnerabilities that allows a remote authenticated users to execute code as the root user via maliciously crafted meeting room.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.60
Vulnerability allows remote authenticated users to execute code as root, representing a critical security failure with severe fallout.
cooey ↗ severe-fallout -0.60
Critical vulnerability allowing root code execution via buffer overflow.
"Ivanti Pulse Connect Secure Collaboration Suite contains a buffer overflow vulnerabilities that allows a remote authenticated users to execute code as the root user via maliciously crafted meeting room."
AFFECTED FEDRAMP PRODUCTS · 2
PRODUCTSTATUS
Ivanti Neurons for ITSM (Formerly Service Manager)
Ivanti
Authorized
Ivanti Neurons for MDM (Formerly MobileIron)
Ivanti
Authorized