EXPOSURES › CVE-2021-22900
CVE-2021-22900
HIGH ⌖ ON CISA KEV · EXPLOITEDAn authenticated admin on Ivanti Pulse Connect Secure could upload malicious archives to write arbitrary files via an unrestricted file upload flaw.
The vulnerability allowed an authenticated administrator to upload a malicious archive, leading to arbitrary file writes on the system. For DIB organizations, this means compromised admin accounts could be used to inject malware or alter system configurations, directly impacting compliance with NIST 800-171 controls around system integrity and access control. Organizations must ensure all Pulse Connect Secure instances are patched and monitor admin account activity closely.
Shame score — A known unrestricted file upload flaw in an enterprise security product that was actively exploited in the wild, indicating a failure to patch a critical vulnerability before it was weaponized.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Ivanti Pulse Connect Secure contains an unrestricted file upload vulnerability that allows an authenticated administrator to perform a file write via a maliciously crafted archive upload in the administrator web interface.
"Ivanti Pulse Connect Secure contains an unrestricted file upload vulnerability that allows an authenticated administrator to perform a file write via a maliciously crafted archive upload in the administrator web interface."
| PRODUCT | STATUS |
|---|---|
| Ivanti Neurons for ITSM (Formerly Service Manager) Ivanti |
Authorized |
| Ivanti Neurons for MDM (Formerly MobileIron) Ivanti |
Authorized |