Vulnerability Description
In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthenticated remote attacker can send a specially crafted URI to perform an arbitrary file reading vulnerability .
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ivanti | Connect Secure | 8.2 |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/154176/Pulse-Secure-SSL-VPN-8.1R15.1-8.2-8.ExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/154231/Pulse-Secure-SSL-VPN-File-DisclosureThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/108073Broken LinkThird Party AdvisoryVDB Entry
- https://badpackets.net/over-14500-pulse-secure-vpn-endpoints-vulnerable-to-cve-2Broken LinkThird Party Advisory
- https://devco.re/blog/2019/09/02/attacking-ssl-vpn-part-3-the-golden-Pulse-SecurExploitThird Party Advisory
- https://i.blackhat.com/USA-19/Wednesday/us-19-Tsai-Infiltrating-Corporate-IntranThird Party Advisory
- https://kb.pulsesecure.net/?atype=saNot ApplicableVendor Advisory
- https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44101/Broken LinkPatchVendor Advisory
- https://lists.apache.org/thread.html/ff5fa1837b6bd1b24d18a42faa75e165a4573dbe2d4Mailing List
- https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2019-0010Third Party Advisory
- https://www.kb.cert.org/vuls/id/927237Third Party AdvisoryUS Government Resource
- http://packetstormsecurity.com/files/154176/Pulse-Secure-SSL-VPN-8.1R15.1-8.2-8.ExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/154231/Pulse-Secure-SSL-VPN-File-DisclosureThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/108073Broken LinkThird Party AdvisoryVDB Entry
- https://badpackets.net/over-14500-pulse-secure-vpn-endpoints-vulnerable-to-cve-2Broken LinkThird Party Advisory
FAQ
What is CVE-2019-11510?
CVE-2019-11510 is a vulnerability with a CVSS score of 10.0 (CRITICAL). In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthenticated remote attacker can send a specially crafted URI to perform an arbitrary ...
How severe is CVE-2019-11510?
CVE-2019-11510 has been rated CRITICAL with a CVSS base score of 10.0/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2019-11510?
Check the references section above for vendor advisories and patch information. Affected products include: Ivanti Connect Secure.