CVE-2021-44720
Last modified
CVE-2021-44720 is a high-severity vulnerability rated 7.2/10 on the CVSS scale. In Ivanti Pulse Secure Pulse Connect Secure (PCS) before 9.1R12, the administrator password is stored in the HTML source code of the "Maintenance > Push Configuration > Targets > Target Name" targets.cgi screen. A read-only administrative user can escalate to a read-write administrative role.. EPSS estimates a 2.30% chance of exploitation in the next 30 days.
Description
In Ivanti Pulse Secure Pulse Connect Secure (PCS) before 9.1R12, the administrator password is stored in the HTML source code of the "Maintenance > Push Configuration > Targets > Target Name" targets.cgi screen. A read-only administrative user can escalate to a read-write administrative role.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ivanti | Connect Secure | 9.1 |
| Pulsesecure | Pulse Connect Secure | < 9.1 |
References
- https://gist.github.com/JGarciaSec/2060ec1c8efc1d573a1ddb754c6b4f84Third Party Advisory
- https://kb.pulsesecure.net/?atype=saVendor Advisory
- https://gist.github.com/JGarciaSec/2060ec1c8efc1d573a1ddb754c6b4f84Third Party Advisory
- https://kb.pulsesecure.net/?atype=saVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-44720?
How severe is CVE-2021-44720?
How do I fix CVE-2021-44720?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-44715Acrobat Reader DC version 21.007.20099 (and earlier), 20.004…5.5
- CVE-2021-44716net/http in Go before 1.16.12 and 1.17.x before 1.17.5 allow…7.5
- CVE-2021-44717Go before 1.16.12 and 1.17.x before 1.17.5 on UNIX allows wr…4.8
- CVE-2021-44718wolfSSL through 5.0.0 allows an attacker to cause a denial o…5.9
- CVE-2021-44719Docker Desktop 4.3.0 has Incorrect Access Control.8.4
- CVE-2021-4472The mistral-dashboard plugin for openstack has a local file …6.5
- CVE-2021-44725KNIME Server before 4.13.4 allows directory traversal in a r…7.5
- CVE-2021-44726KNIME Server before 4.13.4 allows XSS via the old WebPortal …6.1
- CVE-2021-4473Tianxin Internet Behavior Management System contains a comma…9.8
- CVE-2021-44730snapd 2.54.2 did not properly validate the location of the s…8.8
- CVE-2021-44731A race condition existed in the snapd 2.54.2 snap-confine bi…7.8
- CVE-2021-44732Mbed TLS before 3.0.1 has a double free in certain out-of-me…9.8
Are you affected by CVE-2021-44720?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
