VDB

CVE-2019-11540

CVE-2019-11540 PUBLISHED CVSS 8.300000190734863 HIGH

In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4 and 8.3RX before 8.3R7.1 and Pulse Policy Secure version 9.0RX before 9.0R3.2 and 5.4RX before 5.4R7.1, an unauthenticated, remote attacker can conduct a session hijacking attack.

EPSS 8.31% · 92.4th percentile

Risk Scores

CVSS 3.0
8.300000190734863
CVSS:3.0/AC:H/AV:N/A:H/C:H/I:H/PR:N/S:C/UI:R
EPSS Score
8.31%
92.4th percentile

Affected Products

VendorProductVersions
n/an/an/a
pulsesecurepulse_policy_secure*, 5.4rx, 9.0r2
ivanticonnect_secure8.3
pulsesecurepulse_connect_secure9.0r2.1, 9.0r3, 9.0r3.1

Timeline

  • CVE Published
  • Aug 10, 2019 PoC Published
  • Dec 2, 2019 PoC Published
  • Jan 20, 2020 PoC Published
  • Feb 25, 2021 PoC Published
  • Apr 14, 2021 EPSS Score
  • Jul 29, 2021 PoC Published
  • Jan 6, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Jun 18, 2024 PoC Published
  • Aug 25, 2024 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›