← Back to CVE List
Vulnerability Intelligence Report
Ivanti Pulse Connect Secure Use-After-Free Vulnerability

CVE-2021-22893

Pulse Connect Secure 9.0R3/9.1R1 and higher is vulnerable to an authentication bypass vulnerability exposed by the Windows File Share Browser and Pulse Secure Collaboration features of Pulse Connect Secure that can allow an unauthenticated user to perform remote arbitrary code execution on the Pulse Connect Secure gateway. This vulnerability has been exploited in the wild.

CISA KEV SSVC: Active Exploitation Automatable Authentication Bypass
CVSS Base Score
10.0
CRITICAL
Exploitability:3.9
Impact Score:6.1
EPSS Probability:47.17%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-287 ↗Improper Authentication - Generic (CWE-287)

Affected Products & Versions

Vendor Product Affected Versions
n/a Pulse Connect Secure PCS 9.0R3 or above, PCS 9.1R1 and above (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

CISA KEV
ACTIVE IN CATALOG
EPSS Score
47.172%
Vulnerability Class
Authentication Bypass

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityHackerOne · Bug Bounty Provider · USA
Reserved2021-01-06T00:00:00
Published2021-04-23T16:29:43
Last Updated2026-08-12T03:55:19

LINK COPIED TO CLIPBOARD