CVE-2019-11538 โ Link Following in Ivanti Connect Secure
Severity
7.7HIGHNVD
EPSS
3.1%
top 13.10%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 26
Latest updateJun 18
Description
In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1RX before 8.1R15.1, an NFS problem could allow an authenticated attacker to access the contents of arbitrary files on the affected device.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:NExploitability: 3.1 | Impact: 4.0
Affected Packages1 packages
๐ดVulnerability Details
2๐ต๏ธThreat Intelligence
1Tenableโถ
CVE-2019-11510: Proof of Concept Available for Arbitrary File Disclosure in Pulse Connect Secureโ2019-08-21
๐ฌCommunity
4HackerOneโถ
Arbitrary File Reading leads to RCE in the Pulse Secure SSL VPN on the https://โโโโโโ (โโโ)โ2024-06-18
HackerOneโถ
Arbitrary File Reading leads to RCE in the Pulse Secure SSL VPN on the https://โโโโโ2021-07-29
HackerOneโถ
Arbitrary File Reading leads to RCE in the Pulse Secure SSL VPN on the https://โโโโ2019-12-02