Vulnerability Details CVE-2019-11543
XSS exists in the admin web console in Pulse Secure Pulse Connect Secure (PCS) 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, and 8.1RX before 8.1R15.1 and Pulse Policy Secure 9.0RX before 9.0R3.2, 5.4RX before 5.4R7.1, and 5.2RX before 5.2R12.1.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 44.1%
CVSS Severity
CVSS v3 Score 8.3
CVSS v2 Score 4.3
Products affected by CVE-2019-11543
-
cpe:2.3:a:ivanti:connect_secure:8.1
-
cpe:2.3:a:ivanti:connect_secure:8.3
-
cpe:2.3:a:pulsesecure:pulse_connect_secure:8.1r1.0
-
cpe:2.3:a:pulsesecure:pulse_connect_secure:8.1rx
-
cpe:2.3:a:pulsesecure:pulse_connect_secure:8.3rx
-
cpe:2.3:a:pulsesecure:pulse_connect_secure:9.0r1
-
cpe:2.3:a:pulsesecure:pulse_connect_secure:9.0r2
-
cpe:2.3:a:pulsesecure:pulse_connect_secure:9.0r2.1
-
cpe:2.3:a:pulsesecure:pulse_connect_secure:9.0r3
-
cpe:2.3:a:pulsesecure:pulse_connect_secure:9.0r3.1
-
cpe:2.3:a:pulsesecure:pulse_connect_secure:9.0r3.2
-
cpe:2.3:a:pulsesecure:pulse_connect_secure:9.0rx
-
cpe:2.3:a:pulsesecure:pulse_policy_secure:5.2r1.0
-
cpe:2.3:a:pulsesecure:pulse_policy_secure:5.2r10.0
-
cpe:2.3:a:pulsesecure:pulse_policy_secure:5.2r11.0
-
cpe:2.3:a:pulsesecure:pulse_policy_secure:5.2r2.0
-
cpe:2.3:a:pulsesecure:pulse_policy_secure:5.2r3.0
-
cpe:2.3:a:pulsesecure:pulse_policy_secure:5.2r3.2
-
cpe:2.3:a:pulsesecure:pulse_policy_secure:5.2r4.0
-
cpe:2.3:a:pulsesecure:pulse_policy_secure:5.2r5.0
-
cpe:2.3:a:pulsesecure:pulse_policy_secure:5.2r6.0
-
cpe:2.3:a:pulsesecure:pulse_policy_secure:5.2r7.0
-
cpe:2.3:a:pulsesecure:pulse_policy_secure:5.2r7.1
-
cpe:2.3:a:pulsesecure:pulse_policy_secure:5.2r8.0
-
cpe:2.3:a:pulsesecure:pulse_policy_secure:5.2r9.0
-
cpe:2.3:a:pulsesecure:pulse_policy_secure:5.2r9.1
-
cpe:2.3:a:pulsesecure:pulse_policy_secure:5.2rx
-
cpe:2.3:a:pulsesecure:pulse_policy_secure:5.4r1
-
cpe:2.3:a:pulsesecure:pulse_policy_secure:5.4r2
-
cpe:2.3:a:pulsesecure:pulse_policy_secure:5.4r2.1
-
cpe:2.3:a:pulsesecure:pulse_policy_secure:5.4r3
-
cpe:2.3:a:pulsesecure:pulse_policy_secure:5.4r4
-
cpe:2.3:a:pulsesecure:pulse_policy_secure:5.4r5
-
cpe:2.3:a:pulsesecure:pulse_policy_secure:5.4r5.2
-
cpe:2.3:a:pulsesecure:pulse_policy_secure:5.4r6
-
cpe:2.3:a:pulsesecure:pulse_policy_secure:5.4r6.1
-
cpe:2.3:a:pulsesecure:pulse_policy_secure:5.4r7
-
cpe:2.3:a:pulsesecure:pulse_policy_secure:5.4rx
-
cpe:2.3:a:pulsesecure:pulse_policy_secure:9.0r1
-
cpe:2.3:a:pulsesecure:pulse_policy_secure:9.0r2
-
cpe:2.3:a:pulsesecure:pulse_policy_secure:9.0r2.1
-
cpe:2.3:a:pulsesecure:pulse_policy_secure:9.0r3
-
cpe:2.3:a:pulsesecure:pulse_policy_secure:9.0r3.1
-
cpe:2.3:a:pulsesecure:pulse_policy_secure:9.0rx