Junglewise Threat Intelligence

CVE-2019-11539: Ivanti Pulse Connect Secure and Policy Secure Command Injection Vulnerability

CVE-2019-11539 · Severity: critical · CVSS 7.2 · Exploited in the wild · Published 2021-11-03

Vendors: Ivanti.

Executive brief

A command injection vulnerability in the admin web interface of Ivanti (formerly Pulse Secure) Pulse Connect Secure and Pulse Policy Secure allows an authenticated administrator to execute arbitrary OS commands. This vulnerability has been observed being exploited in the wild and is included in CISA's Known Exploited Vulnerabilities catalog.

Affected products

  • Ivanti Pulse Connect Secure 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, 8.1RX before 8.1R15.1
  • Ivanti Pulse Policy Secure 9.0RX before 9.0R3.2, 5.4RX before 5.4R7.1, 5.3RX before 5.3R12.1, 5.2RX before 5.2R12.1, 5.1RX before 5.1R15.1

Timeline

  • 2019-09-02: disclosed: Public blog post detailing exploitation published by Devcore
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog