CVE-2019-11539

Scores

EPSS

0.939high93.9%
0%20%40%60%80%100%

Percentile: 93.9%

CVSS

7.2high3.x
0246810

CVSS Score: 7.2/10

All CVSS Scores

CVSS 3.x
7.2

Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CVSS 2.0
6.5

Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Description

In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1RX before 8.1R15.1 and Pulse Policy Secure version 9.0RX before 9.0R3.2, 5.4RX before 5.4R7.1, 5.3RX before 5.3R12.1, 5.2RX before 5.2R12.1, and 5.1RX before 5.1R15.1, the admin web interface allows an authenticated attacker to inject and execute commands.

Scaner-VS 7 — a modern vulnerability management solution

Uses this database for vulnerability detection. High-speed search, cross-platform, advanced configuration audit, and flexible filtering. Suitable for organizations of any size.
Learn more about Scaner-VS 7

Sources

nvd

CWEs

CWE-78

Related Vulnerabilities

Exploits

Exploit ID: 47354

Source: exploitdb

URL: https://www.exploit-db.com/exploits/47354

Exploit ID: 47700

Source: exploitdb

URL: https://www.exploit-db.com/exploits/47700

Exploit ID: CVE-2019-11539

Source: github-poc

URL: https://github.com/0xDezzy/CVE-2019-11539

Vulnerable Software (3)

Type: Configuration

Vendor: *

Product: connect_secure

Operating System: * * *

Trait:
{  "cpe_match": [    {      "cpe23uri": "cpe:2.3:a:ivanti:connect_secure:8.1:-:*:*:*:*:*:*",      "vulnerable": true    },    {      "cpe23uri": "cpe:2.3:a:ivanti:connect_secure:8.1:r1.0:*:*:*:...

Source: nvd

Type: Configuration

Vendor: *

Product: policy_secure

Operating System: * * *

Trait:
{  "cpe_match": [    {      "cpe23uri": "cpe:2.3:a:ivanti:connect_secure:8.1:-:*:*:*:*:*:*",      "vulnerable": true    },    {      "cpe23uri": "cpe:2.3:a:ivanti:connect_secure:8.1:r1.0:*:*:*:...

Source: nvd

Type: Configuration

Vendor: *

Product: pulse_policy_secure

Operating System: * * *

Trait:
{  "cpe_match": [    {      "cpe23uri": "cpe:2.3:a:ivanti:connect_secure:8.1:-:*:*:*:*:*:*",      "vulnerable": true    },    {      "cpe23uri": "cpe:2.3:a:ivanti:connect_secure:8.1:r1.0:*:*:*:...

Source: nvd

End of list