PT-2021-5238 · Pulse Secure · Pulse Connect Secure
Published
2021-05-03
·
Updated
2025-02-04
·
CVE-2021-22894
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Pulse Connect Secure versions prior to 9.1R11.4
Description
A buffer overflow issue exists, allowing a remote authenticated attacker to execute arbitrary code as the root user via maliciously crafted meeting room data. This can be exploited by a remote attacker, potentially leading to code execution.
Recommendations
For versions prior to 9.1R11.4, update to version 9.1R11.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the meeting room feature until a patch is applied.
Fix
RCE
Buffer Overflow
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Pulse Connect Secure