CVE-2019-11539
KEV ransomware PoC ×2massAuthenticated Command Injection in Ivanti Pulse Connect Secure and Policy Secure
CISA: Ivanti Pulse Connect Secure and Policy Secure Command Injection Vulnerability
Ivanti/Pulse Secure Pulse Connect Secure and Pulse Policy Secure contain an OS command injection flaw (CWE-78) in the admin web interface. An authenticated attacker can send crafted requests to the administrative web interface to inject and execute arbitrary operating-system commands on the appliance. Successful exploitation gives full control of the VPN or network access control appliance, enabling data theft, persistence, and pivoting into the corporate intranet. Any organization running an affected Pulse Connect Secure (9.0RX/8.3RX/8.2RX/8.1RX) or Pulse Policy Secure (9.0RX/5.4RX/5.3RX/5.2RX/5.1RX) release is exposed, especially internet-facing VPN gateways. Exploitation is very active: the bug is in CISA's KEV, public research chained it with CVE-2019-11510 into an unauthenticated RCE chain, APT groups and Black Kingdom ransomware operators have been reported exploiting Pulse VPN flaws, and EPSS estimates a 98.5% probability of exploitation within 30 days.
What to do: Upgrade Pulse Connect Secure to 9.0R3.4+ (or 8.3R7.1+, 8.2R12.1+, 8.1R15.1+) and Pulse Policy Secure/Policy Secure to 9.0R3.2+ (or 5.4R7.1+, 5.3R12.1+, 5.2R12.1+, 5.1R15.1+) per vendor instructions. Restrict exposure of the admin web interface to trusted networks, rotate administrative credentials, and hunt for signs of compromise on appliances that were internet-exposed, particularly where the chained CVE-2019-11510 file-read flaw may also have been exploited.
| ivanti / pulsesecure Pulse Connect Secure | 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, 8.1RX before 8.1R15.1 |
| ivanti / pulsesecure Pulse Policy Secure | 9.0RX before 9.0R3.2, 5.4RX before 5.4R7.1, 5.3RX before 5.3R12.1, 5.2RX before 5.2R12.1, 5.1RX before 5.1R15.1 |
| ivanti / pulsesecure Policy Secure | Same ranges as Pulse Policy Secure (9.0RX before 9.0R3.2, 5.4RX before 5.4R7.1, 5.3RX before 5.3R12.1, 5.2RX before 5.2R12.1, 5.1RX before 5.1R15.1) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1RX before 8.1R15.1 and Pulse Policy Secure version 9.0RX before 9.0R3.2, 5.4RX before 5.4R7.1, 5.3RX before 5.3R12.1, 5.2RX before 5.2R12.1, and 5.1RX before 5.1R15.1, the admin web interface allows an authenticated attacker to inject and execute commands.
- Affected
- Ivanti Pulse Connect Secure and Pulse Policy Secure
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Known
- Vendors
- ivantipulsesecure
- Products
- connect secure, policy secure, pulse policy secure
- Weakness
- CWE-78
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H