← Vulnerability feed

Vulnerability record · CVE-2019-11510 · published 8 May 2019

CVE-2019-11510: Pulse Connect Secure path traversal allows unauthenticated file read

Ivanti · Connect Secure

Pulse Connect Secure versions 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4 contain a path traversal (CWE-22) flaw. An unauthenticated remote attacker can send a crafted URI to read arbitrary files on the appliance. Because these devices terminate VPN access, exposed file contents can include credentials and session material that enable deeper intrusion.

10.0 CVSS 3.1 Critical CISA KEV since 3 Nov 2021 Known ransomware use EPSS 100% · top 0.1% CWE-22 · Path traversal
10.0CVSS 3.1 base score, v2 7.5
100%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
23References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthenticated remote attacker can send a specially crafted URI to perform an arbitrary file reading vulnerability .

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityUnauthenticated network-reachable arbitrary file read on an internet-facing VPN with CVSS 10, KEV listing, ransomware use and near-certain EPSS score.

What it is

Pulse Connect Secure versions 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4 contain a path traversal (CWE-22) flaw. An unauthenticated remote attacker can send a crafted URI to read arbitrary files on the appliance. Because these devices terminate VPN access, exposed file contents can include credentials and session material that enable deeper intrusion.

Impact

An attacker gains unauthenticated read access to arbitrary files on the VPN appliance, which can expose stored credentials, session tokens and configuration data. That access has been used as a stepping stone toward full compromise of the device and the internal network behind it.

Attack surface

Reachable over the network via a crafted URI to the Pulse Connect Secure web interface; the CVSS vector shows no privileges and no user interaction required. Any internet-exposed or otherwise reachable management/VPN interface is in scope.

Exploitation

Listed in CISA KEV since 2021-11-03 with known ransomware campaign use, and EPSS 30-day probability is 0.99999 (99.996th percentile). Multiple references are tagged Exploit, confirming public exploit material exists.

What to do

  • Upgrade to Pulse Connect Secure 8.2R12.1, 8.3R7.1, 9.0R3.4 or later per the vendor advisory SA44101.
  • If patching cannot be done immediately, remove the appliance from direct internet exposure or restrict access to trusted source addresses.
  • Rotate credentials, certificates and session secrets that may have been stored on or readable from the device.
  • Run the vendor's Integrity Checker Tool to look for prior compromise before trusting the appliance.
  • Monitor vendor and CISA guidance for follow-on fixes, since this flaw has been chained with others.

Detection

  • Search web/proxy logs for requests containing path traversal sequences (../, encoded variants) against Pulse Connect Secure URIs.
  • Alert on unexpected outbound connections or new processes/files on the VPN appliance.
  • Review authentication logs for logins using accounts whose credentials resided on the appliance.
  • Use the vendor Integrity Checker Tool output and compare file hashes against known-good baselines.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2019-11510 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Ivanti Pulse Connect Secure Arbitrary File Read Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://packetstormsecurity.com/files/154176/Pulse-Secure-SSL-VPN-8.1R15.1-8.2-8.3-9.0-Arbitrary-File-Disclosure.html ExploitThird Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/154231/Pulse-Secure-SSL-VPN-File-Disclosure-NSE.html Third Party AdvisoryVDB Entry
http://www.securityfocus.com/bid/108073 Broken LinkThird Party AdvisoryVDB Entry
https://badpackets.net/over-14500-pulse-secure-vpn-endpoints-vulnerable-to-cve-2019-11510/ Broken LinkThird Party Advisory
https://devco.re/blog/2019/09/02/attacking-ssl-vpn-part-3-the-golden-Pulse-Secure-ssl-vpn-rce-chain-with-Twitter-as-case ExploitThird Party Advisory
https://i.blackhat.com/USA-19/Wednesday/us-19-Tsai-Infiltrating-Corporate-Intranet-Like-NSA.pdf Third Party Advisory
https://kb.pulsesecure.net/?atype=sa Not ApplicableVendor Advisory
https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44101/ Broken LinkPatchVendor Advisory
https://lists.apache.org/thread.html/ff5fa1837b6bd1b24d18a42faa75e165a4573dbe2d434910c15fd08a%40%3Cuser.guacamole.apache Mailing List
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2019-0010 Third Party Advisory
https://www.kb.cert.org/vuls/id/927237 Third Party AdvisoryUS Government Resource
http://packetstormsecurity.com/files/154176/Pulse-Secure-SSL-VPN-8.1R15.1-8.2-8.3-9.0-Arbitrary-File-Disclosure.html ExploitThird Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/154231/Pulse-Secure-SSL-VPN-File-Disclosure-NSE.html Third Party AdvisoryVDB Entry
http://www.securityfocus.com/bid/108073 Broken LinkThird Party AdvisoryVDB Entry
https://badpackets.net/over-14500-pulse-secure-vpn-endpoints-vulnerable-to-cve-2019-11510/ Broken LinkThird Party Advisory
https://devco.re/blog/2019/09/02/attacking-ssl-vpn-part-3-the-golden-Pulse-Secure-ssl-vpn-rce-chain-with-Twitter-as-case ExploitThird Party Advisory
https://i.blackhat.com/USA-19/Wednesday/us-19-Tsai-Infiltrating-Corporate-Intranet-Like-NSA.pdf Third Party Advisory
https://kb.pulsesecure.net/?atype=sa Not ApplicableVendor Advisory
https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44101/ Broken LinkPatchVendor Advisory
https://lists.apache.org/thread.html/ff5fa1837b6bd1b24d18a42faa75e165a4573dbe2d434910c15fd08a%40%3Cuser.guacamole.apache Mailing List
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2019-0010 Third Party Advisory
https://www.kb.cert.org/vuls/id/927237 Third Party AdvisoryUS Government Resource
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-11510 US Government Resource

Track CVE-2019-11510 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2021-22893Ivanti Pulse Connect Secure authentication bypass and use-after-free enabling RCEPulse Connect Secure 9.0R3/9.1R1 and higher contains an authentication bypass exposed through the Windows File Share Browser and Pulse Secure Collabo…KEVEPSS 47%analysed9.8CVE-2025-22457Ivanti Connect Secure, Policy Secure and ZTA Gateways stack buffer overflow RCEA stack-based buffer overflow (CWE-121/CWE-787) in Ivanti Connect Secure, Policy Secure and ZTA Gateways allows a remote, unauthenticated attacker to…KEVEPSS 100%analysed9.1CVE-2024-21887Ivanti Connect Secure and Policy Secure web component command injectionIvanti Connect Secure and Policy Secure (9.x, 22.x) contain a command injection flaw (CWE-77) in web components. An authenticated administrator can s…KEVEPSS 100%analysed9.0CVE-2025-0282Ivanti Connect Secure stack buffer overflow enables unauthenticated RCEA stack-based buffer overflow (CWE-121/CWE-787) in Ivanti Connect Secure, Policy Secure and Neurons for ZTA gateways lets a remote, unauthenticated a…KEVEPSS 100%analysed8.8CVE-2021-22894Pulse Connect Secure buffer overflow allows root code executionPulse Connect Secure before 9.1R11.4 contains a buffer overflow reachable through a maliciously crafted meeting room. A remote authenticated attacker…KEVEPSS 41%analysed8.8CVE-2021-22899Pulse Connect Secure command injection via Windows Resource ProfilesPulse Connect Secure before 9.1R11.4 contains a command injection flaw (CWE-77) in the Windows Resource Profiles feature. An attacker who can authent…KEVEPSS 23%analysed8.2CVE-2024-21893Ivanti Connect Secure SAML SSRF allows unauthenticated resource accessThe SAML component of Ivanti Connect Secure, Policy Secure and Neurons for ZTA contains a server-side request forgery flaw that lets an attacker reac…KEVEPSS 100%analysed8.2CVE-2023-46805Ivanti Connect Secure and Policy Secure web component authentication bypassThe web component of Ivanti Connect Secure (ICS) 9.x and 22.x and Ivanti Policy Secure fails to properly enforce authentication, letting a remote att…KEVEPSS 100%analysed

Source: NIST National Vulnerability Database (record CVE-2019-11510), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.