← Back to browse · API

CVE-2021-22900

Severity
HIGH
CVSS
7.2
EPSS
0.14146
Risk score
58.75
CISA KEV
Yes
PoC
No
Published
2021-11-03
Modified
2021-11-03
First seen
2026-08-07
Aliases
EUVD-2021-10032, GHSA-J8CW-M86F-RXGW
Products
Ivanti:Pulse Connect Secure, n/a:Pulse Secure Secure Fixed in 9.1R11.4
Sources
euvd EUVD-2021-10032
cisa.gov CVE-2021-22900

Description

Ivanti Pulse Connect Secure contains an unrestricted file upload vulnerability that allows an authenticated administrator to perform a file write via a maliciously crafted archive upload in the administrator web interface.

References