PT-2021-5238 · Pulse Secure · Pulse Connect Secure

Published

2021-05-03

·

Updated

2025-02-04

·

CVE-2021-22894

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Pulse Connect Secure versions prior to 9.1R11.4
Description A buffer overflow issue exists, allowing a remote authenticated attacker to execute arbitrary code as the root user via maliciously crafted meeting room data. This can be exploited by a remote attacker, potentially leading to code execution.
Recommendations For versions prior to 9.1R11.4, update to version 9.1R11.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the meeting room feature until a patch is applied.

Fix

RCE

Buffer Overflow

Code Injection

Weakness Enumeration

Related Identifiers

BDU:2021-06041
CVE-2021-22894

Affected Products

Pulse Connect Secure