Vulnerability record · CVE-2021-22894 · published 27 May 2021
CVE-2021-22894: Pulse Connect Secure buffer overflow allows root code execution
Ivanti · Connect Secure
Pulse Connect Secure before 9.1R11.4 contains a buffer overflow reachable through a maliciously crafted meeting room. A remote authenticated attacker can exploit it to execute arbitrary code as root, making it a serious risk for internet-facing VPN appliances.
Description
A buffer overflow vulnerability exists in Pulse Connect Secure before 9.1R11.4 allows a remote authenticated attacker to execute arbitrary code as the root user via maliciously crafted meeting room.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityIt is a network-reachable root code execution flaw in an internet-facing VPN appliance that CISA lists as known exploited and EPSS scores above the 98th percentile.
What it is
Pulse Connect Secure before 9.1R11.4 contains a buffer overflow reachable through a maliciously crafted meeting room. A remote authenticated attacker can exploit it to execute arbitrary code as root, making it a serious risk for internet-facing VPN appliances.
Impact
Successful exploitation gives the attacker arbitrary code execution with root privileges on the Connect Secure appliance. That level of access can expose VPN credentials, session data and the internal network the appliance protects.
Attack surface
The flaw is reached over the network (AV:N) and requires the attacker to be authenticated with low privileges (PR:L); no user interaction is needed (UI:N). It is triggered by a crafted meeting room, indicating the collaboration/meeting component is the entry point.
Exploitation
CISA added this to the Known Exploited Vulnerabilities catalog on 2021-11-03, indicating real-world exploitation, and EPSS gives a 30-day probability of 0.41284 (98.6th percentile). No ransomware campaign use is documented in the record.
What to do
- Upgrade Pulse Connect Secure to 9.1R11.4 or later as directed by the vendor advisory.
- If immediate patching is not possible, restrict or disable the meeting room/collaboration functionality and limit authenticated access to trusted users.
- Reduce the appliance's internet exposure where feasible and enforce strong authentication and least privilege for VPN accounts.
- Monitor vendor guidance and CISA KEV required actions, applying the update by the stated due date.
- After patching, rotate credentials and review appliance logs for signs of prior compromise.
Detection
- Review Pulse Connect Secure logs for unusual meeting room creation or access activity, especially from low-privilege accounts.
- Hunt for unexpected processes, child processes or command execution originating from the Connect Secure web/collaboration components.
- Monitor for outbound connections or file changes on the appliance that do not match normal administrative activity.
- Check for authentication anomalies and new or modified accounts on the appliance that could indicate post-exploitation.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2021-22894 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Ivanti Pulse Connect Secure Collaboration Suite Buffer Overflow Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44784/?kA23Z000000boUWSAY | Broken LinkVendor Advisory |
| https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44784/?kA23Z000000boUWSAY | Broken LinkVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-22894 | US Government Resource |
Track CVE-2021-22894 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-22894), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.