LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2021-22900: Ivanti Pulse Connect Secure Unrestricted File Upload Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 3, 2021
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
May 3, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2021-22900 to its Known Exploited Vulnerabilities catalog on Nov 3, 2021, with a federal patch deadline of May 3, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Ivanti Pulse Connect Secure contains an unrestricted file upload vulnerability that allows an authenticated administrator to perform a file write via a maliciously crafted archive upload in the…

CVE-2021-22900 is an unrestricted file upload flaw in Ivanti Pulse Connect Secure. An authenticated administrator can upload a maliciously crafted archive through the administrator web interface and cause an arbitrary file write on the appliance. Because Pulse Connect Secure often sits at the edge as a remote-access gateway, a successful write can let an attacker plant code or alter configuration, turning a compromised admin session into deeper control of the VPN infrastructure.

Organizations that rely on this product for employee or partner access should treat the issue as high priority until they confirm their appliances are patched per the vendor advisory. Public detail beyond the CISA description is limited; always verify exact impact and fixed releases against Ivanti’s guidance.

How it works

The weakness is classified as CWE-94 (code injection) and manifests as unrestricted file upload. In normal operation the administrator web interface accepts archive uploads for legitimate maintenance or configuration tasks. The vulnerable logic fails to adequately constrain the contents or destination of those archives. An attacker who already holds valid administrator credentials can craft an archive that, when processed, writes attacker-chosen files to locations the appliance should not allow. Once a file is written, the attacker may achieve code execution, persistence, or further configuration changes, depending on what the written content can influence. No unauthenticated remote path is described; the prerequisite is an authenticated admin session.

Am I affected? How to find it in your systems

Pulse Connect Secure appliances are typically deployed as physical or virtual VPN gateways, often in DMZs or edge networks, and are managed through a dedicated administrator web console. Inventory every instance by:

Because exploitation requires administrator authentication, look for anomalous admin logins, unexpected archive uploads, or file-system changes around the time of any suspected compromise. Centralized logs from the appliance, authentication servers, and any web-application firewall in front of the admin interface are the primary telemetry sources. Confirm exact version ranges and indicators of compromise against the vendor advisory; do not rely solely on generic signatures.

How to remediate

The required action is to apply the updates published by Ivanti for Pulse Connect Secure. Follow the vendor’s installation and reboot procedures exactly; partial or out-of-order updates can leave residual risk. After patching:

Document the change and retain pre- and post-patch configuration snapshots for later audit.

If you can't patch immediately

Until the vendor update can be applied, reduce exposure with compensating controls:

These measures do not eliminate the vulnerability; they only raise the bar until the official patch is installed.

If your data may have been exposed

Actively exploited edge vulnerabilities frequently lead to broader network compromise and data theft. If you have reason to believe an attacker obtained administrator access or wrote malicious files, treat the incident as a potential breach: isolate the appliance, preserve logs and disk images, and begin forensic review. As a quick additional check, you can run a free exposure scan of your email addresses against known breach data sets to see whether credentials or personal information have already appeared in public dumps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedIvanti · Pulse Connect Secure
WeaknessCWE-94
Added to CISA KEVNov 3, 2021
Federal patch deadlineMay 3, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities