← Vulnerability feed

Vulnerability record · CVE-2021-22899 · published 27 May 2021

CVE-2021-22899: Pulse Connect Secure command injection via Windows Resource Profiles

Ivanti · Connect Secure

Pulse Connect Secure before 9.1R11.4 contains a command injection flaw (CWE-77) in the Windows Resource Profiles feature. An attacker who can authenticate to the appliance can inject commands that execute on the underlying system, giving code execution on a VPN gateway that typically sits at the network edge.

8.8 CVSS 3.1 High CISA KEV since 3 Nov 2021 EPSS 23% · top 2.3% CWE-77 · Command injection
8.8CVSS 3.1 base score, v2 6.5
23%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
3References
17 Jun 2026Last modified by NVD

Description

A command injection vulnerability exists in Pulse Connect Secure before 9.1R11.4 allows a remote authenticated attacker to perform remote code execution via Windows Resource Profiles Feature

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityIt is a network-reachable authenticated RCE on an edge VPN appliance that is in CISA KEV with elevated EPSS, though it requires valid credentials.

What it is

Pulse Connect Secure before 9.1R11.4 contains a command injection flaw (CWE-77) in the Windows Resource Profiles feature. An attacker who can authenticate to the appliance can inject commands that execute on the underlying system, giving code execution on a VPN gateway that typically sits at the network edge.

Impact

A remote authenticated attacker gains remote code execution with the privileges of the affected service, allowing full compromise of confidentiality, integrity and availability of the appliance.

Attack surface

Reached over the network through the Windows Resource Profiles feature; the CVSS vector (AV:N/PR:L/UI:N) indicates a low-privileged authenticated account is required and no user interaction is needed.

Exploitation

Listed in CISA KEV since 2021-11-03 with a required action to apply vendor updates, and EPSS shows a 30-day probability of roughly 0.23 (97.6th percentile), indicating observed exploitation activity.

What to do

  • Upgrade Pulse Connect Secure to 9.1R11.4 or later as directed by the vendor advisory.
  • Restrict and audit accounts with access to the Windows Resource Profiles feature; remove unused or low-trust accounts.
  • Limit management and administrative access to trusted networks or VPN-only paths.
  • Monitor for and investigate any signs of compromise on appliances that ran a vulnerable version before patching.

Detection

  • Review appliance and host logs for unexpected child processes or command execution spawned by the Pulse Connect Secure service.
  • Alert on configuration changes to Windows Resource Profiles, especially from low-privileged accounts.
  • Hunt for outbound connections or tooling on the appliance consistent with post-exploitation activity.
  • Correlate authentication logs for unusual or newly used accounts accessing the resource profiles feature.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2021-22899 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Ivanti Pulse Connect Secure Command Injection Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-22899 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2021-22893Ivanti Pulse Connect Secure authentication bypass and use-after-free enabling RCEPulse Connect Secure 9.0R3/9.1R1 and higher contains an authentication bypass exposed through the Windows File Share Browser and Pulse Secure Collabo…KEVEPSS 47%analysed10.0CVE-2019-11510Pulse Connect Secure path traversal allows unauthenticated file readPulse Connect Secure versions 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4 contain a path traversal (CWE-22) flaw. An unauthentica…KEVEPSS 100%analysed9.8CVE-2025-22457Ivanti Connect Secure, Policy Secure and ZTA Gateways stack buffer overflow RCEA stack-based buffer overflow (CWE-121/CWE-787) in Ivanti Connect Secure, Policy Secure and ZTA Gateways allows a remote, unauthenticated attacker to…KEVEPSS 100%analysed9.1CVE-2024-21887Ivanti Connect Secure and Policy Secure web component command injectionIvanti Connect Secure and Policy Secure (9.x, 22.x) contain a command injection flaw (CWE-77) in web components. An authenticated administrator can s…KEVEPSS 100%analysed9.0CVE-2025-0282Ivanti Connect Secure stack buffer overflow enables unauthenticated RCEA stack-based buffer overflow (CWE-121/CWE-787) in Ivanti Connect Secure, Policy Secure and Neurons for ZTA gateways lets a remote, unauthenticated a…KEVEPSS 100%analysed8.8CVE-2021-22894Pulse Connect Secure buffer overflow allows root code executionPulse Connect Secure before 9.1R11.4 contains a buffer overflow reachable through a maliciously crafted meeting room. A remote authenticated attacker…KEVEPSS 41%analysed8.2CVE-2024-21893Ivanti Connect Secure SAML SSRF allows unauthenticated resource accessThe SAML component of Ivanti Connect Secure, Policy Secure and Neurons for ZTA contains a server-side request forgery flaw that lets an attacker reac…KEVEPSS 100%analysed8.2CVE-2023-46805Ivanti Connect Secure and Policy Secure web component authentication bypassThe web component of Ivanti Connect Secure (ICS) 9.x and 22.x and Ivanti Policy Secure fails to properly enforce authentication, letting a remote att…KEVEPSS 100%analysed

Source: NIST National Vulnerability Database (record CVE-2021-22899), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.