Back to overview

CVE-2019-11510

CRITICAL KEV CISA Exploitation: ACTIVE Ransomware noto
9.9
CVSS 3.0
Description
In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthenticated remote attacker can send a specially crafted URI to perform an arbitrary file reading vulnerability .

Metadata

CVE ID
CVE-2019-11510
State
PUBLISHED
Assigner
mitre
Reserved
2019-04-24 00:00 UTC
Published
2019-05-08 16:18 UTC
Last updated
2025-10-21 23:45 UTC
Primary CWE
CWE-22
CWE-22 Improper Limitation of a Pathname to a Restricted Dir…
Vendor / Product
n/a / n/a
Sources
cve.org  ·  NVD

Severity & Metrics

9.9 CRITICAL CVSS 3.0
CVSS:3.0/AC:L/AV:N/A:H/C:H/I:H/PR:L/S:C/UI:N
SSVC — CISA Coordinator
Exploitation
ACTIVE
Automatable
yes
Tech. Impact
total
CISA Known Exploited Vulnerability
Vulnerability name
Ivanti Pulse Connect Secure Arbitrary File Read Vulnerability
Vendor
Ivanti
Product
Pulse Connect Secure
Added to KEV
2021-11-03
Due date
2022-05-03
Ransomware
Known use
Required action
Apply updates per vendor instructions.
CISA description
Ivanti Pulse Connect Secure contains an arbitrary file read vulnerability that allows an unauthenticated remote attacker with network access via HTTPS to send a specially crafted URI.
Affected products (1)
VendorProductPlatformVersions
n/a n/a n/a
Weakness (CWE)
CWESourceDescription
cna n/a
CWE-22 adp CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSS scores (1)
ScoreSeverityVersionSourceVector
9.9 CRITICAL 3.0 cna CVSS:3.0/AC:L/AV:N/A:H/C:H/I:H/PR:L/S:C/UI:N
Back to overview