CVE-2019-11539 PUBLISHED KEV CVSS 8 HIGH

In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1RX before 8.1R15.1 and Pulse Policy Secure version 9.0RX before 9.0R3.2, 5.4RX before 5.4R7.1, 5.3RX before 5.3R12.1, 5.2RX before 5.2R12.1, and 5.1RX before 5.1R15.1, the admin web interface allows an authenticated attacker to inject and execute commands.

EPSS 93.91% · 99.9th percentile

Risk Scores

CVSS v3.0
8
CVSS:3.0/AC:H/AV:N/A:H/C:H/I:H/PR:H/S:C/UI:N
EPSS Score
93.91%
99.9th percentile

Affected Products

VendorProductVersions
n/an/an/a
pulsesecurepulse_policy_secure5.4rx, 5.4r7, 5.4r6.1
ivanticonnect_secure8.3, 8.1, 8.1
ivantipolicy_secure9.0, 9.0, 9.0

Timeline

References

Open in Interactive Console →