Umbra Wiki cve cve/CVE-2019-11539
Back to wiki

CVE-2019-11539 — Ivanti Pulse Connect Secure and Policy Secure Command Injection Vulnerability

provenance: imported · CVE: CVE-2019-11539

CVE-2019-11539: Ivanti Pulse Connect Secure and Policy Secure Command Injection Vulnerability

CISA Known Exploited Vulnerability (KEV)

Vendor / project Ivanti
Product Pulse Connect Secure and Pulse Policy Secure
Date added 2021-11-03
Due date 2022-05-03
Ransomware campaign use Known

Description

Ivanti Pulse Connect Secure and Policy Secure allows an authenticated attacker from the admin web interface to inject and execute commands.

Required action (CISA)

Apply updates per vendor instructions.

Notes

https://nvd.nist.gov/vuln/detail/CVE-2019-11539

References

  • NVD: https://nvd.nist.gov/vuln/detail/CVE-2019-11539
  • KEV catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog