CVE-2021-31922

moderate-risk
Published 2021-05-14

An HTTP Request Smuggling vulnerability in Pulse Secure Virtual Traffic Manager before 21.1 could allow an attacker to smuggle an HTTP request through an HTTP/2 Header. This vulnerability is resolved in 21.1, 20.3R1, 20.2R1, 20.1R2, 19.2R4, and 18.2R3.

Do I need to act?

-
0.19% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
7
CVSS 7.5/10 High
NETWORK / LOW complexity

Affected Products (10)

Virtual Traffic Manager
Virtual Traffic Manager
Virtual Traffic Manager
Virtual Traffic Manager
Virtual Traffic Manager
Virtual Traffic Manager
Virtual Traffic Manager
Virtual Traffic Manager
Virtual Traffic Manager
Virtual Traffic Manager

Affected Vendors

43
/ 100
moderate-risk
Severity 26/34 · High
Exploitability 1/34 · Minimal
Exposure 16/34 · Moderate