Skip to main content
Mallory
CriticalCISA KEVExploited in the wildPublic exploit

Authentication Bypass RCE in Pulse Connect Secure

IdentifiersCVE-2021-22893CWE-288

CVE-2021-22893 affects Pulse Connect Secure (PCS) 9.0R3/9.1R1 and later. The vulnerability is exposed through the Windows File Share Browser and Pulse Secure Collaboration features and allows an unauthenticated attacker to bypass authentication on the PCS gateway and achieve remote arbitrary code execution. Multiple sources in the provided content describe the issue as an authentication bypass leading to remote arbitrary file execution / remote arbitrary code execution on the Pulse Connect Secure gateway. The flaw was actively exploited in the wild, including in campaigns against government, defense, financial, and other organizations. Reporting in the provided content also ties exploitation to deployment of webshells and follow-on malware on compromised PCS appliances.

Share:
For your environment

Are you exposed to this one?

Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.

ANALYST BRIEF

Impact, mitigation & remediation

What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.

Impact

What an attacker gets, and what they’ve been doing with it.

Successful exploitation can result in full compromise of the Pulse Connect Secure gateway. The provided content states attackers used this vulnerability for initial access and then deployed webshells and malware enabling arbitrary command execution, authentication and MFA bypass, credential harvesting, persistence across patching or upgrades, and broader follow-on intrusion activity. Observed campaigns targeted U.S. government agencies, critical infrastructure, defense industrial base entities, financial organizations, and other private-sector victims. Because PCS is an internet-facing VPN/security gateway, compromise can expose credentials, facilitate lateral movement into internal networks, and support long-term espionage or other post-compromise operations.

Mitigation

If you can’t patch tonight, do this now.

Where immediate patching is not possible, disable the Windows File Share Browser and Pulse Secure Collaboration features, including use of the vendor mitigation XML/workaround file referenced in the advisories. The content notes these mitigations disable certain features and may not automatically re-enable after patching. Additional mitigation and response steps in the provided material include running the Integrity Tool, reviewing unauthenticated request logs and web server logs for suspicious HTTP POST activity, inspecting /webserver/htdocs/dana-na/ and subdirectories for new or modified malicious files/webshells, centralizing logs, and performing password resets for accounts that traversed the PCS environment.

Remediation

Patch, then assume compromise.

Apply the vendor fix for affected Pulse Connect Secure systems. The provided content states Pulse Secure/Ivanti released patch version 9.1R.11.4 on 2021-05-03 to address CVE-2021-22893, and later releases also addressed related issues. Organizations should upgrade vulnerable PCS appliances to a fixed version, use the Pulse Secure Connect Integrity Tool / Integrity Checker Tool to identify compromise, and if compromise is detected or suspected, begin incident response immediately. The content also recommends resetting all credentials associated with the Pulse Secure environment because harvested credentials may remain usable after appliance remediation, and investigating the broader environment for persistence or lateral movement.
PUBLIC EXPLOITS

Exploits

No valid public exploits. Mallory filtered out 1 candidate as fakes, detection scripts, or README-only repos.

VALID 0 / 1 TOTALView more in app

All candidate exploits were filtered out by Mallory's validation.

EXPOSURE SURFACE

Affected products & vendors

Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.

VendorProductType
IvantiConnect Secureapplication
Pulse SecurePulse Connect Secureapplication

Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets are affected, which adversaries are exploiting it right now, which detections to deploy, and what to do tonight.
Exposure mapping

Query your assets running an affected version, and investigate the blast radius.

Threat actor evidence7

Every observed campaign linking this CVE to a named adversary.

Associated malware40

Malware families riding this exploit, with evidence and IOCs.

Detection signatures1

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Vendor-by-vendor mapping

Cross-references every affected SKU, including bundled OEM variants.

Social activity

Community discussion across Reddit, Mastodon, and other social sources.