Vulnerability Intelligence Report
Ivanti Pulse Connect Secure and Policy Secure Command Injection Vulnerability
CVE-2019-11539
In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1RX before 8.1R15.1 and Pulse Policy Secure version 9.0RX before 9.0R3.2, 5.4RX before 5.4R7.1, 5.3RX before 5.3R12.1, 5.2RX before 5.2R12.1, and 5.1RX before 5.1R15.1, the admin web interface allows an authenticated attacker to inject and execute commands.
CISA KEV
SSVC: Active Exploitation
CVSS Base Score
8.0
HIGH
Exploitability:1.4
Impact Score:6.1
EPSS Probability:98.62%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-78 ↗CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| ivanti | connect_secure | 8.1, 8.2, 8.3, 9.0 |
| ivanti | policy_secure | 9.0 |
| pulsesecure | pulse_policy_secure | 5.1r1.0, 5.1r1.1, 5.1r2.0, 5.1r2.1, 5.1r3.0, 5.1r3.2, 5.1r4.0, 5.1r5.0, 5.1r6.0, 5.1r7.0, 5.1r8.0, 5.1r9.0, 5.1r9.1, 5.1r10.0, 5.1r11.0, 5.1r11.1, 5.1r12.0, 5.1r12.1, 5.1r13.0, 5.1r14.0, 5.2r1.0, 5.2r2.0, 5.2r3.0, 5.2r3.2, 5.2r4.0, 5.2r5.0, 5.2r6.0, 5.2r7.0, 5.2r7.1, 5.2r8.0, 5.2r9.0, 5.2r9.1, 5.2r10.0, 5.2r11.0, 5.2rx, 5.3r1.0, 5.3r1.1, 5.3r2.0, 5.3r3.0, 5.3r3.1, 5.3r4.0, 5.3r4.1, 5.3r5.0, 5.3r5.1, 5.3r5.2, 5.3r6.0, 5.3r7.0, 5.3r8.0, 5.3r8.1, 5.3r8.2, 5.3r9.0, 5.3r10., 5.3r11.0, 5.3r12.0, 5.3rx, 5.4r1, 5.4r2, 5.4r2.1, 5.4r3, 5.4r4, 5.4r5, 5.4r5.2, 5.4r6, 5.4r6.1, 5.4r7, 5.4rx |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | MITRE Corporation · N/A · USA |
| Reserved | 2019-04-25T00:00:00 |
| Published | 2019-04-26T01:39:36 |
| Last Updated | 2025-10-21T23:45:38 |
Community Chatter & Buzz