SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2019-11539

Ivanti Pulse Connect Secure and Policy Secure Command Injection Vulnerability

KEVHIGH 7.2EPSS 98.5%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 3 May 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1RX before 8.1R15.1 and Pulse Policy Secure version 9.0RX before 9.0R3.2, 5.4RX before 5.4R7.1, 5.3RX before 5.3R12.1, 5.2RX before 5.2R12.1, and 5.1RX before 5.1R15.1, the admin web interface allows an authenticated attacker to inject and execute commands.

CVSS 3.1
7.2 HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS
98.54% probability · 100th percentile
CISA KEV
Listed 3 November 2021 · due 3 May 2022 · used in ransomware campaigns
Weakness
CWE-78
Affected
ivanti/connect secure · ivanti/policy secure · pulsesecure/pulse policy secure
Source
cve@mitre.org

CISA notes

Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2019-11539

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.