TROYANOSYVIRUS
Back to CVEs

CVE-2019-11539

HIGHCISA KEV
7.2

Description

In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1RX before 8.1R15.1 and Pulse Policy Secure version 9.0RX before 9.0R3.2, 5.4RX before 5.4R7.1, 5.3RX before 5.3R12.1, 5.2RX before 5.2R12.1, and 5.1RX before 5.1R15.1, the admin web interface allows an authenticated attacker to inject and execute commands.

CVE Details

CVSS v3.1 Score7.2
SeverityHIGH
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack VectorNETWORK
ComplexityLOW
Privileges RequiredHIGH
User InteractionNONE
Published4/26/2019
Last Modified11/6/2025
Sourcekev
Honeypot Sightings0

CISA KEV

VendorIvanti
ProductPulse Connect Secure and Pulse Policy Secure
Vulnerability NameIvanti Pulse Connect Secure and Policy Secure Command Injection Vulnerability
KEV Date Added2021-11-03
Remediation Due Date2022-05-03
Ransomware UseKnown

Affected Products

ivanti:connect_secureivanti:policy_securepulsesecure:pulse_policy_secure

Weaknesses (CWE)

CWE-78CWE-78

References

http://www.securityfocus.com/bid/108073(af854a3a-2127-422b-91ae-364da2661108)
https://www.kb.cert.org/vuls/id/927237(af854a3a-2127-422b-91ae-364da2661108)

IOC Correlations

No correlations recorded

This product uses data from the NVD API but is not endorsed or certified by the NVD.