peter bassill · operator
$ cve CVE-2019-11540 JSON

CVE-2019-11540

9.8
CRITICAL · CVSS 3.1 · EPSS 8.3% (pctl 95)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4 and 8.3RX before 8.3R7.1 and Pulse Policy Secure version 9.0RX before 9.0R3.2 and 5.4RX before 5.4R7.1, an unauthenticated, remote attacker can conduct a session hijacking attack.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS8.26% — more likely to be exploited than 95% of all CVEs
On CISA KEVno
Public exploitnone known
Published2019-04-26
Last modified2026-06-17

Affected (3)

VendorProduct
ivanticonnect secure
pulsesecurepulse connect secure
pulsesecurepulse policy secure

References

→ the Explorer  ·  watch your stack  ·  NVD