CVE-2019-11540 PUBLISHED CVSS 8.300000190734863 HIGH

In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4 and 8.3RX before 8.3R7.1 and Pulse Policy Secure version 9.0RX before 9.0R3.2 and 5.4RX before 5.4R7.1, an unauthenticated, remote attacker can conduct a session hijacking attack.

EPSS 6.52% · 91.0th percentile

Risk Scores

CVSS v3.0
8.300000190734863
CVSS:3.0/AC:H/AV:N/A:H/C:H/I:H/PR:N/S:C/UI:R
EPSS Score
6.52%
91.0th percentile

Affected Products

VendorProductVersions
n/an/an/a
pulsesecurepulse_policy_secure9.0rx, 5.4r6, 5.4r6.1
ivanticonnect_secure8.3
pulsesecurepulse_connect_secure9.0r1, 9.0r2, 9.0r2.1

Timeline

References

Open in Interactive Console →