CVE-2019-11213 is a high-severity vulnerability affecting Pulse Secure Pulse Desktop Client and Network Connect, allowing attackers to replay and spoof sessions by accessing session tokens, leading to unauthorized user access. This requires a pre-compromised endpoint for successful exploitation. The CVSS score is 8.1, indicating high impact on confidentiality, integrity, and availability, with high attack complexity. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 9.0r1, < 9.0r3CPE matchmatch criteria | cpe:2.3:a:ivanti:connect_secure:*:*:*:*:*:*:*:* | ||
>= 8.1r1.0, <= 8.1r14.0CPE matchmatch criteria | cpe:2.3:a:pulsesecure:pulse_connect_secure:*:*:*:*:*:*:*:* | ||
>= 8.3r1, < 8.3r7CPE matchmatch criteria | cpe:2.3:a:pulsesecure:pulse_connect_secure:*:*:*:*:*:*:*:* | ||
>= 5.0r1.0, < 5.3r7CPE matchmatch criteria | cpe:2.3:a:pulsesecure:pulse_secure_desktop_client:*:*:*:*:*:*:*:* | ||
>= 9.0r1, < 9.0r3CPE matchmatch criteria | cpe:2.3:a:pulsesecure:pulse_secure_desktop_client:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.