Skip to content
COOEY

EXPOSURES › CVE-2021-22899

CVE-2021-22899

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2021-22899 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 78/100 rceexploited-in-wildunpatched

Ivanti Pulse Connect Secure suffered a command injection vulnerability allowing remote authenticated users to execute arbitrary code via Windows File Resource Profiles.

This command injection flaw in Ivanti Pulse Connect Secure enabled remote code execution for authenticated users, directly violating CMMC/NIST 800-171 requirements for preventing unauthorized access and ensuring system integrity. DIB organizations must verify their Ivanti deployments are patched, as this vulnerability was actively exploited in the wild and represents a severe compliance gap if left unaddressed.

Shame score — A known command injection vulnerability in a widely deployed security product was actively exploited in the wild, indicating negligent patching and a failure to protect critical infrastructure.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Ivanti Pulse Connect Secure contains a command injection vulnerability that allows remote authenticated users to perform remote code execution via Windows File Resource Profiles.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.60
Vulnerability allows remote code execution via command injection, a critical flaw with severe security implications.
cooey ↗ severe-fallout -0.60
Critical vulnerability allowing remote code execution via command injection.
"Ivanti Pulse Connect Secure contains a command injection vulnerability that allows remote authenticated users to perform remote code execution via Windows File Resource Profiles."
AFFECTED FEDRAMP PRODUCTS · 2
PRODUCTSTATUS
Ivanti Neurons for ITSM (Formerly Service Manager)
Ivanti
Authorized
Ivanti Neurons for MDM (Formerly MobileIron)
Ivanti
Authorized