CVE-2019-11539 is a critical command injection vulnerability affecting Pulse Connect Secure and Pulse Policy Secure products, allowing an authenticated attacker to execute arbitrary commands via the admin web interface. With a CVSS score of 7.2 (High), it presents a significant risk due to its network-based attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. This vulnerability is actively exploited in the wild, including by ransomware campaigns, and has publicly available exploit code in Metasploit and ExploitDB. Its high EPSS score and extensive community discussion and media coverage underscore its widespread recognition and threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
8.1CPE matchmatch criteria | cpe:2.3:a:ivanti:connect_secure:8.1:-:*:*:*:*:*:* | ||
8.1CPE matchmatch criteria | cpe:2.3:a:ivanti:connect_secure:8.1:r1.0:*:*:*:*:*:* | ||
8.1CPE matchmatch criteria | cpe:2.3:a:ivanti:connect_secure:8.1:r1.1:*:*:*:*:*:* | ||
8.1CPE matchmatch criteria | cpe:2.3:a:ivanti:connect_secure:8.1:r10.0:*:*:*:*:*:* | ||
8.1CPE matchmatch criteria | cpe:2.3:a:ivanti:connect_secure:8.1:r11.0:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.