Skip to main content

Updated advice on Pulse Connect Secure RCE Vulnerability

Advice for UK organisations using Pulse Connect Secure (PCS) VPN appliances.
Art Alex via Getty Images

FireEye published a blog saying that APT actors are actively exploiting vulnerabilities in Pulse Connect VPN appliances.

The NCSC is aware of an unauthenticated remote code execution vulnerability affecting Pulse Connect Secure (PCS) version 9.0R3 and higher (CVE-2021-22893). Pulse Secure says it recently discovered that a limited number of customers have experienced evidence of exploit behaviour on their Pulse Connect Secure (PCS) appliances.

Pulse Secure previously published a workaround as a temporary measure. The upgrade released on 3 May 2021 now replaces this.

 

The NCSC strongly advises UK customers using Pulse Connect Secure VPN devices to regularly run the integrity tool checker provided by the vendor. This tool checks the integrity of the complete file system and finds any additional/modified file(s). This will help identify possible activity resulting from the exploitation of Pulse Secure Connect vulnerabilities.

Organisations should note that running the integrity checker tool requires a reboot. The NCSC recommends that organisations using virtualised Pulse appliances take a snapshot of the device before running the integrity tool check. This will allow organisations to roll back to the snapshot after the tool has run, in order to conduct forensic analysis. Organisations using physical appliances should consider taking a forensic image of the device before running the tool in order to obtain the original details. Organisations should contact Ivanti for further assistance or questions.

The US Department of Homeland Security’s (DHS) Cybersecurity Infrastructure Security Agency (CISA) has published an Emergency Directive on this issue.

Reporting a compromise

Affected UK organisations should report any suspected compromises to the NCSC via the website.