SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2019-11510

Ivanti Pulse Connect Secure Arbitrary File Read Vulnerability

KEVCRITICAL 10.0EPSS 100.0%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 3 May 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthenticated remote attacker can send a specially crafted URI to perform an arbitrary file reading vulnerability .

CVSS 3.1
10.0 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS
100.00% probability · 100th percentile
CISA KEV
Listed 3 November 2021 · due 3 May 2022 · used in ransomware campaigns
Weakness
CWE-22
Affected
ivanti/connect secure
Source
cve@mitre.org

CISA notes

Apply updates per vendor instructions. Reference CISA's ED 21-03 (https://www.cisa.gov/news-events/directives/ed-21-03-mitigate-pulse-connect-secure-product-vulnerabilities) for further guidance and requirements. Note: The due date for addressing this vulnerability aligns with the requirements outlined in ED 21-03. https://nvd.nist.gov/vuln/detail/CVE-2019-11510

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.