Rewterz
Rewterz Threat Advisory – CVE-2021-29461 – Discord-Recon Local File Include Vulnerability
April 21, 2021
Rewterz
Rewterz Threat Advisory – Multiple Google Chrome Vulnerabilities
April 21, 2021

Rewterz Threat Advisory – CVE-2021-22893 – Pulse Connect Secure RCE Vulnerability

Severity

High

Analysis Summary

CVE-2021-22893

The Zero-day Pulse Connect Secure authentication bypass vulnerability allows an attacker to run an arbitrary code on the Pulse Connect Secure Gateway. A remote, unauthenticated attacker can send a specially crafted HTTP request to the victim to exploit the vulnerability and gain access to the target system.

Impact

  • Remote Code Execution
  • URL-Based Attacks

Affected Vendors

Pulse Secure

Affected Products

  • Pulse Connect Secure 9.1RX
  • Pulse Connect Secure 9.0RX

Remediation

Upgrade to the latest Pulse Connect Secure server software version 9.1R.11.4 and for updates visit

https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44784

A software update is expected to release in early May.