Junglewise Threat Intelligence

CVE-2019-11510: Ivanti Pulse Connect Secure Arbitrary File Read Vulnerability

CVE-2019-11510 · Severity: critical · CVSS 10 · Exploited in the wild · Published 2021-11-03

Executive brief

Ivanti Pulse Connect Secure (formerly Pulse Secure) contains an arbitrary file read vulnerability due to improper limitation of a pathname to a restricted directory. An unauthenticated remote attacker can exploit this by sending a specially crafted URI to access sensitive files on the system.

Affected products

  • Ivanti (Pulse Secure) Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4

Timeline

  • 2019-04-24: advisory: Initial vendor advisory SA44101 published by Pulse Secure
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2021-11-03: disclosed: NVD publication date