CVE-2021-44720
Last modified
CVE-2021-44720 is a high-severity vulnerability rated 7.2/10 on the CVSS scale. In Ivanti Pulse Secure Pulse Connect Secure (PCS) before 9.1R12, the administrator password is stored in the HTML source code of the "Maintenance > Push Configuration > Targets > Target Name" targets.cgi screen. A read-only administrative user can escalate to a read-write administrative role.. EPSS estimates a 2.30% chance of exploitation in the next 30 days.
Description
In Ivanti Pulse Secure Pulse Connect Secure (PCS) before 9.1R12, the administrator password is stored in the HTML source code of the "Maintenance > Push Configuration > Targets > Target Name" targets.cgi screen. A read-only administrative user can escalate to a read-write administrative role.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ivanti | Connect Secure | 9.1 |
| Pulsesecure | Pulse Connect Secure | < 9.1 |
References
- https://gist.github.com/JGarciaSec/2060ec1c8efc1d573a1ddb754c6b4f84Third Party Advisory
- https://kb.pulsesecure.net/?atype=saVendor Advisory
- https://gist.github.com/JGarciaSec/2060ec1c8efc1d573a1ddb754c6b4f84Third Party Advisory
- https://kb.pulsesecure.net/?atype=saVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-44720?
How severe is CVE-2021-44720?
How do I fix CVE-2021-44720?
Are you affected by CVE-2021-44720?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
