CVE-2019-11541
published 2019-04-26CVE-2019-11541: In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, and 8.2RX before 8.2R12.1, users using SAML authentication with the…
PriorityP347high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
3.99%
89.2th percentile
In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, and 8.2RX before 8.2R12.1, users using SAML authentication with the Reuse Existing NC (Pulse) Session option may see authentication leaks.
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ivanti | connect_secure | — | — |
| ivanti | connect_secure | — | — |
| pulsesecure | pulse_connect_secure | — | — |
| pulsesecure | pulse_connect_secure | — | — |
| pulsesecure | pulse_connect_secure | — | — |
| pulsesecure | pulse_connect_secure | — | — |
| pulsesecure | pulse_connect_secure | — | — |
| pulsesecure | pulse_connect_secure | — | — |
| pulsesecure | pulse_connect_secure | — | — |
| pulsesecure | pulse_connect_secure | — | — |
| pulsesecure | pulse_connect_secure | — | — |
| pulsesecure | pulse_connect_secure | — | — |
| pulsesecure | pulse_connect_secure | — | — |
| pulsesecure | pulse_connect_secure | — | — |
| pulsesecure | pulse_connect_secure | — | — |
| pulsesecure | pulse_connect_secure | — | — |
| pulsesecure | pulse_connect_secure | — | — |
| pulsesecure | pulse_connect_secure | — | — |
| pulsesecure | pulse_connect_secure | — | — |
| pulsesecure | pulse_connect_secure | — | — |
| pulsesecure | pulse_connect_secure | — | — |
| pulsesecure | pulse_connect_secure | — | — |
| pulsesecure | pulse_connect_secure | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv3.08.3HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ivanti
Ivanti Security Advisory: CVE-2019-11541
vendor_ivanti·2019-04-26·CVSS 7.5
CVE-2019-11541 [HIGH] Ivanti Security Advisory: CVE-2019-11541
Ivanti Security Advisory: CVE-2019-11541
In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, and 8.2RX before 8.2R12.1, users using SAML authentication with the Reuse Existing NC (Pulse) Session option may see authentication leaks.
CVE IDs: CVE-2019-11541
CVSS Base Score: 7.5
Severity: HIGH
GHSA
GHSA-xvm3-rxj9-vf93: In Pulse Secure Pulse Connect Secure version 9
ghsa_unreviewed·2022-05-24
CVE-2019-11541 [HIGH] GHSA-xvm3-rxj9-vf93: In Pulse Secure Pulse Connect Secure version 9
In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, and 8.2RX before 8.2R12.1, users using SAML authentication with the Reuse Existing NC (Pulse) Session option may see authentication leaks.
No detection rules found.
No public exploits indexed.
http://www.securityfocus.com/bid/108073https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44101https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44101/https://www.kb.cert.org/vuls/id/927237http://www.securityfocus.com/bid/108073https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44101https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44101/https://www.kb.cert.org/vuls/id/927237
2019-04-26
Published