CVE-2019-11539
In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1RX before 8.1R15.1 and Pulse...
Basic Information
- CVE State
- PUBLISHED
- Reserved Date
- April 25, 2019
- Published Date
- April 26, 2019
- Last Updated
- February 03, 2025
- Vendor
- n/a
- Product
- n/a
- Description
- In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1RX before 8.1R15.1 and Pulse Policy Secure version 9.0RX before 9.0R3.2, 5.4RX before 5.4R7.1, 5.3RX before 5.3R12.1, 5.2RX before 5.2R12.1, and 5.1RX before 5.1R15.1, the admin web interface allows an authenticated attacker to inject and execute commands.
CVSS Scores
CVSS v3.0
8.0 - HIGH
Vector: CVSS:3.0/AC:H/AV:N/A:H/C:H/I:H/PR:H/S:C/UI:N
SSVC Information
- Exploitation
- active
- Technical Impact
- total
References
https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44101
http://www.securityfocus.com/bid/108073
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2019-0010
https://i.blackhat.com/USA-19/Wednesday/us-19-Tsai-Infiltrating-Corporate-Intranet-Like-NSA.pdf
http://packetstormsecurity.com/files/154376/Pulse-Secure-8.1R15.1-8.2-8.3-9.0-SSL-VPN-Remote-Code-Execution.html
https://devco.re/blog/2019/09/02/attacking-ssl-vpn-part-3-the-golden-Pulse-Secure-ssl-vpn-rce-chain-with-Twitter-as-case-study/
https://www.kb.cert.org/vuls/id/927237
http://packetstormsecurity.com/files/155277/Pulse-Secure-VPN-Arbitrary-Command-Execution.html
http://packetstormsecurity.com/files/162092/Pulse-Secure-VPN-Arbitrary-Command-Execution.html
Known Exploited Vulnerability Information
Source | Added Date |
---|---|
CISA | 2021-11-03 00:00:00 UTC |
Scanner Integrations
Scanner | URL | Date Detected |
---|---|---|
Metasploit | https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/pulse_secure_cmd_exec.rb | 2025-04-29 11:01:14 UTC |
Potential Proof of Concepts
Warning: These PoCs have not been tested and could contain malware. Use at your own risk.
pulse_secure_cmd_exec
Type: metasploit • Created: Unknown
Metasploit module for CVE-2019-11539
0xDezzy/CVE-2019-11539
Type: github • Created: 2019-09-04 13:06:02 UTC • Stars: 132
Exploit for the Post-Auth RCE vulnerability in Pulse Secure Connect