CVE-2021-44720: High severity ivanti pulse connect secure vulnerability
In Ivanti Pulse Secure Pulse Connect Secure (PCS) before 9.1R12, the administrator password is stored in the HTML source code of the "Maintenance > Push Configuration > Targets > Target Name" targets.cgi screen. A read-only administrative user can escalate to a read-write administrative role.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-44720?
CVE-2021-44720 is a vulnerability in Ivanti Pulse Secure Pulse Connect Secure (PCS) before 9.1R12 where the administrator password is stored in the HTML source code.
What is the severity of CVE-2021-44720?
The severity of CVE-2021-44720 is high with a CVSS score of 7.2.
Which software versions are affected by CVE-2021-44720?
The software versions affected by CVE-2021-44720 are Pulse Connect Secure before 9.1R12.
How can an attacker exploit CVE-2021-44720?
An attacker can exploit CVE-2021-44720 by accessing the HTML source code and obtaining the administrator password.
How can I fix CVE-2021-44720?
To fix CVE-2021-44720, update Ivanti Pulse Secure Pulse Connect Secure (PCS) to version 9.1R12 or later.