Vulnerability Details CVE-2019-11509
In Pulse Secure Pulse Connect Secure (PCS) before 8.1R15.1, 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4 and Pulse Policy Secure (PPS) before 5.1R15.1, 5.2 before 5.2R12.1, 5.3 before 5.3R15.1, 5.4 before 5.4R7.1, and 9.0 before 9.0R3.2, an authenticated attacker (via the admin web interface) can exploit Incorrect Access Control to execute arbitrary code on the appliance.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.073
EPSS Ranking 91.2%
CVSS Severity
CVSS v3 Score 8.8
CVSS v2 Score 6.5
Products affected by CVE-2019-11509
-
cpe:2.3:a:ivanti:connect_secure:8.1
-
cpe:2.3:a:ivanti:connect_secure:8.2
-
cpe:2.3:a:ivanti:connect_secure:8.3
-
cpe:2.3:a:ivanti:connect_secure:9.0
-
cpe:2.3:a:ivanti:policy_secure:9.0
-
cpe:2.3:a:pulsesecure:pulse_policy_secure:5.2
-
cpe:2.3:a:pulsesecure:pulse_policy_secure:5.4