CVE-2021-31922

An HTTP Request Smuggling vulnerability in Pulse Secure Virtual Traffic Manager before 21.1 could allow an attacker to smuggle an HTTP request through an HTTP/2 Header. This vulnerability is resolved in 21.1, 20.3R1, 20.2R1, 20.1R2, 19.2R4, and 18.2R3.
HTTP Request/Response Smuggling
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 41%
VendorProductVersion
pulsesecurevirtual_traffic_manager
𝑥
≤ 18.1
pulsesecurevirtual_traffic_manager
18.3 ≤
𝑥
≤ 19.1
pulsesecurevirtual_traffic_manager
18.2
pulsesecurevirtual_traffic_manager
18.2:r1
pulsesecurevirtual_traffic_manager
19.2
pulsesecurevirtual_traffic_manager
19.2:r1
pulsesecurevirtual_traffic_manager
19.2:r2
pulsesecurevirtual_traffic_manager
19.3
pulsesecurevirtual_traffic_manager
20.1
pulsesecurevirtual_traffic_manager
20.2
pulsesecurevirtual_traffic_manager
20.3
𝑥
= Vulnerable software versions