CVE-2019-11540 is a critical session hijacking vulnerability affecting Pulse Secure Pulse Connect Secure and Pulse Policy Secure versions prior to specific updates. An unauthenticated, remote attacker can exploit this flaw with low complexity, potentially leading to complete compromise of confidentiality, integrity, and availability. While not listed on the CISA KEV catalog, the vulnerability has a high EPSS score and significant community discussion, indicating potential for exploitation, though no public exploit code is currently available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
8.3CPE matchmatch criteria | cpe:2.3:a:ivanti:connect_secure:8.3:*:*:*:*:*:*:* | ||
8.3rxCPE matchmatch criteria | cpe:2.3:a:pulsesecure:pulse_connect_secure:8.3rx:*:*:*:*:*:*:* | ||
9.0r1CPE matchmatch criteria | cpe:2.3:a:pulsesecure:pulse_connect_secure:9.0r1:*:*:*:*:*:*:* | ||
9.0r2CPE matchmatch criteria | cpe:2.3:a:pulsesecure:pulse_connect_secure:9.0r2:*:*:*:*:*:*:* | ||
9.0r2.1CPE matchmatch criteria | cpe:2.3:a:pulsesecure:pulse_connect_secure:9.0r2.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.