EXPOSURES › CVE-2021-22899
CVE-2021-22899
HIGH ⌖ ON CISA KEV · EXPLOITEDIvanti Pulse Connect Secure suffered a command injection vulnerability allowing remote authenticated users to execute arbitrary code via Windows File Resource Profiles.
This command injection flaw in Ivanti Pulse Connect Secure enabled remote code execution for authenticated users, directly violating CMMC/NIST 800-171 requirements for preventing unauthorized access and ensuring system integrity. DIB organizations must verify their Ivanti deployments are patched, as this vulnerability was actively exploited in the wild and represents a severe compliance gap if left unaddressed.
Shame score — A known command injection vulnerability in a widely deployed security product was actively exploited in the wild, indicating negligent patching and a failure to protect critical infrastructure.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Ivanti Pulse Connect Secure contains a command injection vulnerability that allows remote authenticated users to perform remote code execution via Windows File Resource Profiles.
"Ivanti Pulse Connect Secure contains a command injection vulnerability that allows remote authenticated users to perform remote code execution via Windows File Resource Profiles."
| PRODUCT | STATUS |
|---|---|
| Ivanti Neurons for ITSM (Formerly Service Manager) Ivanti |
Authorized |
| Ivanti Neurons for MDM (Formerly MobileIron) Ivanti |
Authorized |