TROYANOSYVIRUS
Retour aux CVEs

CVE-2019-11539

HIGHCISA KEV
7.2

Description

In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1RX before 8.1R15.1 and Pulse Policy Secure version 9.0RX before 9.0R3.2, 5.4RX before 5.4R7.1, 5.3RX before 5.3R12.1, 5.2RX before 5.2R12.1, and 5.1RX before 5.1R15.1, the admin web interface allows an authenticated attacker to inject and execute commands.

Details CVE

Score CVSS v3.17.2
SeveriteHIGH
Vecteur CVSSCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Vecteur d'attaqueNETWORK
ComplexiteLOW
Privileges requisHIGH
Interaction utilisateurNONE
Publie4/26/2019
Derniere modification11/6/2025
Sourcekev
Observations honeypot0

CISA KEV

FournisseurIvanti
ProduitPulse Connect Secure and Pulse Policy Secure
Nom vulnerabiliteIvanti Pulse Connect Secure and Policy Secure Command Injection Vulnerability
Date ajout KEV2021-11-03
Date limite remediation2022-05-03
Utilise dans ransomwareKnown

Produits affectes

ivanti:connect_secureivanti:policy_securepulsesecure:pulse_policy_secure

Faiblesses (CWE)

CWE-78CWE-78

References

http://www.securityfocus.com/bid/108073(af854a3a-2127-422b-91ae-364da2661108)
https://www.kb.cert.org/vuls/id/927237(af854a3a-2127-422b-91ae-364da2661108)

Correlations IOC

Aucune correlation enregistree

This product uses data from the NVD API but is not endorsed or certified by the NVD.