HIGH KEV Used in ransomware campaigns ⚠
In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1RX before 8.1R15.1 and Pulse Policy Secure version 9.0RX before 9.0R3.2, 5.4RX before 5.4R7.1, 5.3RX before 5.3R12.1, 5.2RX before 5.2R12.1, and 5.1RX before 5.1R15.1, the admin web interface allows an authenticated attacker to inject and execute commands
Published Apr 26, 2019 ·Due May 3, 2022
7.2
HIGHCVSS 3.1
EPSS 98.54%
Description
In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1RX before 8.1R15.1 and Pulse Policy Secure version 9.0RX before 9.0R3.2, 5.4RX before 5.4R7.1, 5.3RX before 5.3R12.1, 5.2RX before 5.2R12.1, and 5.1RX before 5.1R15.1, the admin web interface allows an authenticated attacker to inject and execute commands.
Affected products
No data.
OR
- 8.1
- 8.1
- 8.1
- 8.1
- 8.1
- 8.1
- 8.1
- 8.1
- 8.1
- 8.1
- 8.1
- 8.1
- 8.1
- 8.1
- 8.1
- 8.1
- 8.1
- 8.1
- 8.1
- 8.1
- 8.1
- 8.1
- 8.1
- 8.1
- 8.1
- 8.2
- 8.2
- 8.2
- 8.2
- 8.2
- 8.2
- 8.2
- 8.2
- 8.2
- 8.2
- 8.2
- 8.2
- 8.2
- 8.2
- 8.2
- 8.2
- 8.2
- 8.2
- 8.2
- 8.2
- 8.2
- 8.2
- 8.3
- 8.3
- 8.3
- 8.3
- 8.3
- 8.3
- 8.3
- 8.3
- 8.3
- 8.3
- 8.3
- 8.3
- 8.3
- 9.0
- 9.0
- 9.0
- 9.0
- 9.0
- 9.0
- 9.0
- 9.0
- 9.0
- 9.0
- 9.0
- 9.0
- 5.1r1.0
- 5.1r1.1
- 5.1r2.0
- 5.1r2.1
- 5.1r3.0
- 5.1r3.2
- 5.1r4.0
- 5.1r5.0
- 5.1r6.0
- 5.1r7.0
- 5.1r8.0
- 5.1r9.0
- 5.1r9.1
- 5.1r10.0
- 5.1r11.0
- 5.1r11.1
- 5.1r12.0
- 5.1r12.1
- 5.1r13.0
- 5.1r14.0
- 5.2r1.0
- 5.2r2.0
- 5.2r3.0
- 5.2r3.2
- 5.2r4.0
- 5.2r5.0
- 5.2r6.0
- 5.2r7.0
- 5.2r7.1
- 5.2r8.0
- 5.2r9.0
- 5.2r9.1
- 5.2r10.0
- 5.2r11.0
- 5.2rx
- 5.3r1.0
- 5.3r1.1
- 5.3r2.0
- 5.3r3.0
- 5.3r3.1
- 5.3r4.0
- 5.3r4.1
- 5.3r5.0
- 5.3r5.1
- 5.3r5.2
- 5.3r6.0
- 5.3r7.0
- 5.3r8.0
- 5.3r8.1
- 5.3r8.2
- 5.3r9.0
- 5.3r10.
- 5.3r11.0
- 5.3r12.0
- 5.3rx
- 5.4r1
- 5.4r2
- 5.4r2.1
- 5.4r3
- 5.4r4
- 5.4r5
- 5.4r5.2
- 5.4r6
- 5.4r6.1
- 5.4r7
- 5.4rx
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (11)
- http://packetstormsecurity.com/files/154376/Pulse-Secure-8.1R15.1-8.2-8.3-9.0-SSL-VPN-Remote-Code-Execution.html x_refsource_MISCThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/155277/Pulse-Secure-VPN-Arbitrary-Command-Execution.html x_refsource_MISCThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/162092/Pulse-Secure-VPN-Arbitrary-Command-Execution.html x_refsource_MISCBroken LinkThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/108073 vdb-entryx_refsource_BIDBroken LinkThird Party AdvisoryVDB Entry
- https://devco.re/blog/2019/09/02/attacking-ssl-vpn-part-3-the-golden-Pulse-Secure-ssl-vpn-rce-chain-with-Twitter-as-case-study/ x_refsource_MISCExploitThird Party Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-3210 Advisory
- https://i.blackhat.com/USA-19/Wednesday/us-19-Tsai-Infiltrating-Corporate-Intranet-Like-NSA.pdf x_refsource_MISCExploitThird Party Advisory
- https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44101 x_refsource_CONFIRMThird Party AdvisoryVendor Advisory
- https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2019-0010 x_refsource_CONFIRMThird Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-11539 government-resourceUS Government Resource
- https://www.kb.cert.org/vuls/id/927237 third-party-advisoryx_refsource_CERT-VNThird Party AdvisoryUS Government Resource
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Apr 26, 2019
Updated Oct 21, 2025
Reserved Apr 25, 2019
Link CVE-2019-11539
CISA Vulnrichment
Updated Feb 3, 2025
Red Hat
No data
ENISA EUVD
Assigner mitre
Published Apr 26, 2019
Updated Oct 21, 2025
Exploited since Nov 3, 2021
Link EUVD-2019-3210
GitHub
No data