Skip to content
COOEY

EXPOSURES › CVE-2021-22900

CVE-2021-22900

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2021-22900 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 65/100 rceexploited-in-wildunpatched

An authenticated admin on Ivanti Pulse Connect Secure could upload malicious archives to write arbitrary files via an unrestricted file upload flaw.

The vulnerability allowed an authenticated administrator to upload a malicious archive, leading to arbitrary file writes on the system. For DIB organizations, this means compromised admin accounts could be used to inject malware or alter system configurations, directly impacting compliance with NIST 800-171 controls around system integrity and access control. Organizations must ensure all Pulse Connect Secure instances are patched and monitor admin account activity closely.

Shame score — A known unrestricted file upload flaw in an enterprise security product that was actively exploited in the wild, indicating a failure to patch a critical vulnerability before it was weaponized.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Ivanti Pulse Connect Secure contains an unrestricted file upload vulnerability that allows an authenticated administrator to perform a file write via a maliciously crafted archive upload in the administrator web interface.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.60
Unrestricted file upload flaw in admin interface allows malicious archive writes, exposing enterprise networks to compromise; no praise found in coverage.
cooey ↗ severe-fallout -0.80
NVD confirms unrestricted file upload vulnerability in admin interface, allowing malicious archive writes; no mitigation or praise noted.
"Ivanti Pulse Connect Secure contains an unrestricted file upload vulnerability that allows an authenticated administrator to perform a file write via a maliciously crafted archive upload in the administrator web interface."
sam.gov ↗ severe-fallout +0.00
SAM.gov page unrelated to CVE-2021-22900; no sentiment toward Ivanti.
CISA ↗ severe-fallout +0.00
CISA page unrelated to CVE-2021-22900; no sentiment toward Ivanti.
nypost.com ↗ severe-fallout +0.00
NY Post article unrelated to CVE-2021-22900; no sentiment toward Ivanti.
app.opencve.io ↗ severe-fallout +0.00
OpenCVE page unrelated to CVE-2021-22900; no sentiment toward Ivanti.
sec.cloudapps.cisco.com ↗ severe-fallout +0.00
Cisco page unrelated to CVE-2021-22900; no sentiment toward Ivanti.
www.cvefind.com ↗ severe-fallout +0.00
CVE Find page unrelated to CVE-2021-22900; no sentiment toward Ivanti.
AFFECTED FEDRAMP PRODUCTS · 2
PRODUCTSTATUS
Ivanti Neurons for ITSM (Formerly Service Manager)
Ivanti
Authorized
Ivanti Neurons for MDM (Formerly MobileIron)
Ivanti
Authorized