Vulnerability record · CVE-2021-22900 · published 27 May 2021
CVE-2021-22900: Pulse Connect Secure admin file upload leads to code injection
Ivanti · Connect Secure
Pulse Connect Secure before 9.1R11.4 allows an authenticated administrator to upload a maliciously crafted archive through the administrator web interface, resulting in unrestricted file writes. Because the written files can be executed, this crosses from file upload into code injection on the appliance. It matters because Pulse Connect Secure is a remote-access gateway, so compromise of the device exposes the protected network.
Description
A vulnerability allowed multiple unrestricted uploads in Pulse Connect Secure before 9.1R11.4 that could lead to an authenticated administrator to perform a file write via a maliciously crafted archive upload in the administrator web interface.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityThe flaw yields code execution on a network edge device and is in CISA KEV, but it requires a valid administrator account, which limits who can trigger it.
What it is
Pulse Connect Secure before 9.1R11.4 allows an authenticated administrator to upload a maliciously crafted archive through the administrator web interface, resulting in unrestricted file writes. Because the written files can be executed, this crosses from file upload into code injection on the appliance. It matters because Pulse Connect Secure is a remote-access gateway, so compromise of the device exposes the protected network.
Impact
An attacker with administrator access gains the ability to write arbitrary files and achieve code execution on the gateway, giving full control of the appliance and a foothold into the networks it brokers access to.
Attack surface
Reached over the network through the administrator web interface; the CVSS vector (AV:N/PR:H/UI:N) indicates a valid administrator account is required and no user interaction is needed.
Exploitation
Listed in CISA KEV since 2021-11-03 with a required action to apply vendor updates, indicating exploitation in the wild; EPSS 30-day probability is about 14 percent (96th percentile). No ransomware campaign use is recorded.
What to do
- Upgrade Pulse Connect Secure to 9.1R11.4 or later per the vendor advisory.
- Restrict administrator web interface access to trusted management networks and disable it from the public internet.
- Enforce strong unique credentials and MFA for all administrative accounts to limit abuse of the required admin privilege.
- Audit and remove unnecessary administrator accounts, and review recent admin logins and uploads for anomalies.
- If patching is delayed, monitor or block archive uploads through the admin interface.
Detection
- Alert on archive file uploads (.zip, .tar, .gz and similar) submitted through the Pulse Connect Secure administrator interface.
- Monitor for new or modified executable files in web-accessible or system directories on the appliance.
- Review administrator authentication logs for unexpected logins, especially from unfamiliar source IPs.
- Hunt for post-exploitation activity such as new scheduled tasks, web shells, or outbound connections from the gateway.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2021-22900 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Ivanti Pulse Connect Secure Unrestricted File Upload Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44784/?kA23Z000000boUWSAY | Broken LinkVendor Advisory |
| https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44784/?kA23Z000000boUWSAY | Broken LinkVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-22900 | US Government Resource |
Track CVE-2021-22900 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-22900), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.