Vulnerability record · CVE-2019-11539 · published 26 April 2019
CVE-2019-11539: Pulse Secure Connect Secure and Policy Secure admin interface OS command injection
Ivanti · Connect Secure
The admin web interface of Pulse Secure Connect Secure and Policy Secure fails to neutralize input, allowing an authenticated attacker to inject and execute operating system commands. Because these are SSL VPN and policy gateways, successful exploitation gives command execution on a perimeter device that brokers access to the internal network.
Description
In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1RX before 8.1R15.1 and Pulse Policy Secure version 9.0RX before 9.0R3.2, 5.4RX before 5.4R7.1, 5.3RX before 5.3R12.1, 5.2RX before 5.2R12.1, and 5.1RX before 5.1R15.1, the admin web interface allows an authenticated attacker to inject and execute commands.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityIt is a network-facing command injection on an SSL VPN gateway, listed in CISA KEV with known ransomware use and near-maximum EPSS probability.
What it is
The admin web interface of Pulse Secure Connect Secure and Policy Secure fails to neutralize input, allowing an authenticated attacker to inject and execute operating system commands. Because these are SSL VPN and policy gateways, successful exploitation gives command execution on a perimeter device that brokers access to the internal network.
Impact
An attacker with admin access to the web interface can run arbitrary commands on the appliance, leading to full compromise of the device and a foothold into the networks it protects.
Attack surface
Reachable over the network via the admin web interface (CVSS AV:N), requiring high privileges (PR:H) and no user interaction (UI:N).
Exploitation
CISA added it to the KEV catalog on 2021-11-03 with known ransomware campaign use, and EPSS shows a 30-day probability of 0.98544 (99.92nd percentile); references include exploit-tagged write-ups.
What to do
- Apply the vendor updates listed in Pulse Secure advisory SA44101 to move off the affected 9.0RX, 8.3RX, 8.2RX, 8.1RX, 5.4RX, 5.3RX, 5.2RX and 5.1RX builds.
- Restrict admin web interface access to trusted management networks and disable or block external exposure.
- Enforce strong unique credentials and MFA for all administrative accounts to reduce the value of the required high privilege.
- Monitor and rotate any credentials or keys stored on or accessible from the appliance after suspected compromise.
- Review KEV remediation requirements and confirm the due date of 2022-05-03 has been met.
Detection
- Hunt appliance and web server logs for unexpected command strings or shell metacharacters in admin interface requests.
- Alert on anomalous child processes or command execution spawned by the web/admin service on the appliance.
- Monitor for outbound connections from the VPN appliance to unusual internal or external hosts.
- Correlate admin logins from unexpected source IPs or at unusual times with subsequent process activity.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2019-11539 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Ivanti Pulse Connect Secure and Policy Secure Command Injection Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2019-11539 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-11539), CISA KEV, FIRST EPSS (scores of 2026-09-16). This page is refreshed as NVD updates the record.