CVE-2019-11510: Ivanti Pulse Connect Secure Arbitrary File Read Vulnerability
Ivanti Pulse Connect Secure contains an arbitrary file read vulnerability that allows an unauthenticated remote attacker with network access via HTTPS to send a specially crafted URI.
Other sources
In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthenticated remote attacker can send a specially crafted URI to perform an arbitrary file reading vulnerability .
— NVD
Affected Software
Remediation
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2019-11510?
CVE-2019-11510 is an arbitrary file read vulnerability in Ivanti Pulse Connect Secure.
How does CVE-2019-11510 impact Ivanti Pulse Connect Secure?
CVE-2019-11510 allows an unauthenticated remote attacker to read arbitrary files on Ivanti Pulse Connect Secure.
Who is affected by CVE-2019-11510?
Users of Ivanti Pulse Connect Secure are affected by CVE-2019-11510.
How can an attacker exploit CVE-2019-11510?
An attacker can exploit CVE-2019-11510 by sending a specially crafted URI via HTTPS.
Is there a fix available for CVE-2019-11510?
Yes, Ivanti has released a fix for CVE-2019-11510. It is recommended to update to the latest version of Ivanti Pulse Connect Secure.