CVE-2019-11539
גבוהה 7.2 מנוצלת בשטח (KEV) בשימוש בכופרה
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Ivanti Pulse Connect Secure and Policy Secure Command Injection Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1RX before 8.1R15.1 and Pulse Policy Secure version 9.0RX before 9.0R3.2, 5.4RX before 5.4R7.1, 5.3RX before 5.3R12.1, 5.2RX before 5.2R12.1, and 5.1RX before 5.1R15.1, the admin web interface allows an authenticated attacker to inject and execute commands.
מדדים
- CVSS 3.1
-
7.2 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 99% (אחוזון 100) נכון ל-30/7/2026
- CWE
- CWE-78
מוצרים מושפעים
ivanti: connect secure; ivanti: policy secure; pulsesecure: pulse policy secure
קישורים
- https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44101 Third Party AdvisoryVendor Advisory
- https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44101 Third Party AdvisoryVendor Advisory
- https://devco.re/blog/2019/09/02/attacking-ssl-vpn-part-3-the-golden-Pulse-Sec… ExploitThird Party Advisory
- https://i.blackhat.com/USA-19/Wednesday/us-19-Tsai-Infiltrating-Corporate-Intr… ExploitThird Party Advisory
- https://devco.re/blog/2019/09/02/attacking-ssl-vpn-part-3-the-golden-Pulse-Sec… ExploitThird Party Advisory
- https://i.blackhat.com/USA-19/Wednesday/us-19-Tsai-Infiltrating-Corporate-Intr… ExploitThird Party Advisory
- http://packetstormsecurity.com/files/154376/Pulse-Secure-8.1R15.1-8.2-8.3-9.0-… Third Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/155277/Pulse-Secure-VPN-Arbitrary-Command… Third Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/162092/Pulse-Secure-VPN-Arbitrary-Command… Broken LinkThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/108073 Broken LinkThird Party AdvisoryVDB Entry