peter bassill · operator
$ cve CVE-2019-11539 JSON

CVE-2019-11539 KEV EXPLOIT

7.2
HIGH · CVSS 3.1 · EPSS 98.5% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2022-05-03.

Description

In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1RX before 8.1R15.1 and Pulse Policy Secure version 9.0RX before 9.0R3.2, 5.4RX before 5.4R7.1, 5.3RX before 5.3R12.1, 5.2RX before 5.2R12.1, and 5.1RX before 5.1R15.1, the admin web interface allows an authenticated attacker to inject and execute commands.

Scoring

CVSS7.2 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS98.54% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-78
On CISA KEVyes — remediate by 2022-05-03
Public exploityes
Published2019-04-26
Last modified2026-06-17

CISA KEV

NameIvanti Pulse Connect Secure and Policy Secure Command Injection Vulnerability
Added2021-11-03
Due2022-05-03
Vendor / productIvanti / Pulse Connect Secure and Pulse Policy Secure
Ransomware useknown

Affected (3)

VendorProduct
ivanticonnect secure
ivantipolicy secure
pulsesecurepulse policy secure

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD