CVE-2019-11510
קריטית 10.0 מנוצלת בשטח (KEV) בשימוש בכופרה
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Ivanti Pulse Connect Secure Arbitrary File Read Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthenticated remote attacker can send a specially crafted URI to perform an arbitrary file reading vulnerability .
מדדים
- CVSS 3.1
-
10.0 (CRITICAL)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H - EPSS — סבירות ניצול
- 100% (אחוזון 100) נכון ל-30/7/2026
- CWE
- CWE-22
מוצרים מושפעים
ivanti: connect secure
קישורים
- https://kb.pulsesecure.net/?atype=sa Not ApplicableVendor Advisory
- https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44101/ Broken LinkPatchVendor Advisory
- https://kb.pulsesecure.net/?atype=sa Not ApplicableVendor Advisory
- https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44101/ Broken LinkPatchVendor Advisory
- http://packetstormsecurity.com/files/154176/Pulse-Secure-SSL-VPN-8.1R15.1-8.2-… ExploitThird Party AdvisoryVDB Entry
- https://devco.re/blog/2019/09/02/attacking-ssl-vpn-part-3-the-golden-Pulse-Sec… ExploitThird Party Advisory
- http://packetstormsecurity.com/files/154176/Pulse-Secure-SSL-VPN-8.1R15.1-8.2-… ExploitThird Party AdvisoryVDB Entry
- https://devco.re/blog/2019/09/02/attacking-ssl-vpn-part-3-the-golden-Pulse-Sec… ExploitThird Party Advisory
- http://packetstormsecurity.com/files/154231/Pulse-Secure-SSL-VPN-File-Disclosu… Third Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/108073 Broken LinkThird Party AdvisoryVDB Entry