Rewterz Threat Advisory – CVE-2021-29461 – Discord-Recon Local File Include Vulnerability
April 21, 2021Rewterz Threat Advisory – Multiple Google Chrome Vulnerabilities
April 21, 2021Rewterz Threat Advisory – CVE-2021-29461 – Discord-Recon Local File Include Vulnerability
April 21, 2021Rewterz Threat Advisory – Multiple Google Chrome Vulnerabilities
April 21, 2021Severity
High
Analysis Summary
CVE-2021-22893
The Zero-day Pulse Connect Secure authentication bypass vulnerability allows an attacker to run an arbitrary code on the Pulse Connect Secure Gateway. A remote, unauthenticated attacker can send a specially crafted HTTP request to the victim to exploit the vulnerability and gain access to the target system.
Impact
- Remote Code Execution
- URL-Based Attacks
Affected Vendors
Pulse Secure
Affected Products
- Pulse Connect Secure 9.1RX
- Pulse Connect Secure 9.0RX
Remediation
Upgrade to the latest Pulse Connect Secure server software version 9.1R.11.4 and for updates visit
https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44784
A software update is expected to release in early May.