CVE-2021-22893
ID: 56d882e6-3999-52cc-94fa-18800d4cc362
STIX ID: report--56d882e6-3999-52cc-94fa-18800d4cc362
Feed Name: Arctic Wolf Blog
Arctic Wolf reports that Ivanti released Pulse Connect Secure 9.1R11.4 to address a zero-day (CVE-2021-22893, CVSS 10.0) allowing unauthenticated remote code execution — observed exploited in the wild — plus three additional critical post-authentication vulnerabilities. Organizations are strongly advised to apply the 9.1R11.4 update to affected Pulse Connect Secure appliances immediately, note the upgrade is for appliances (not clients), be aware of a known certificate issue when upgrading from very old versions, and remove any previously applied workarounds after patching.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
