← Vulnerability feed

Vulnerability record · CVE-2019-11539 · published 26 April 2019

CVE-2019-11539: Pulse Secure Connect Secure and Policy Secure admin interface OS command injection

Ivanti · Connect Secure

The admin web interface of Pulse Secure Connect Secure and Policy Secure fails to neutralize input, allowing an authenticated attacker to inject and execute operating system commands. Because these are SSL VPN and policy gateways, successful exploitation gives command execution on a perimeter device that brokers access to the internal network.

7.2 CVSS 3.1 High CISA KEV since 3 Nov 2021 Known ransomware use EPSS 99% · top 0.1% CWE-78 · OS command injection
7.2CVSS 3.1 base score, v2 6.5
99%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
3Affected product versions listed by NVD
19References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1RX before 8.1R15.1 and Pulse Policy Secure version 9.0RX before 9.0R3.2, 5.4RX before 5.4R7.1, 5.3RX before 5.3R12.1, 5.2RX before 5.2R12.1, and 5.1RX before 5.1R15.1, the admin web interface allows an authenticated attacker to inject and execute commands.

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityIt is a network-facing command injection on an SSL VPN gateway, listed in CISA KEV with known ransomware use and near-maximum EPSS probability.

What it is

The admin web interface of Pulse Secure Connect Secure and Policy Secure fails to neutralize input, allowing an authenticated attacker to inject and execute operating system commands. Because these are SSL VPN and policy gateways, successful exploitation gives command execution on a perimeter device that brokers access to the internal network.

Impact

An attacker with admin access to the web interface can run arbitrary commands on the appliance, leading to full compromise of the device and a foothold into the networks it protects.

Attack surface

Reachable over the network via the admin web interface (CVSS AV:N), requiring high privileges (PR:H) and no user interaction (UI:N).

Exploitation

CISA added it to the KEV catalog on 2021-11-03 with known ransomware campaign use, and EPSS shows a 30-day probability of 0.98544 (99.92nd percentile); references include exploit-tagged write-ups.

What to do

  • Apply the vendor updates listed in Pulse Secure advisory SA44101 to move off the affected 9.0RX, 8.3RX, 8.2RX, 8.1RX, 5.4RX, 5.3RX, 5.2RX and 5.1RX builds.
  • Restrict admin web interface access to trusted management networks and disable or block external exposure.
  • Enforce strong unique credentials and MFA for all administrative accounts to reduce the value of the required high privilege.
  • Monitor and rotate any credentials or keys stored on or accessible from the appliance after suspected compromise.
  • Review KEV remediation requirements and confirm the due date of 2022-05-03 has been met.

Detection

  • Hunt appliance and web server logs for unexpected command strings or shell metacharacters in admin interface requests.
  • Alert on anomalous child processes or command execution spawned by the web/admin service on the appliance.
  • Monitor for outbound connections from the VPN appliance to unusual internal or external hosts.
  • Correlate admin logins from unexpected source IPs or at unusual times with subsequent process activity.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2019-11539 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Ivanti Pulse Connect Secure and Policy Secure Command Injection Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://packetstormsecurity.com/files/154376/Pulse-Secure-8.1R15.1-8.2-8.3-9.0-SSL-VPN-Remote-Code-Execution.html Third Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/155277/Pulse-Secure-VPN-Arbitrary-Command-Execution.html Third Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/162092/Pulse-Secure-VPN-Arbitrary-Command-Execution.html Broken LinkThird Party AdvisoryVDB Entry
http://www.securityfocus.com/bid/108073 Broken LinkThird Party AdvisoryVDB Entry
https://devco.re/blog/2019/09/02/attacking-ssl-vpn-part-3-the-golden-Pulse-Secure-ssl-vpn-rce-chain-with-Twitter-as-case ExploitThird Party Advisory
https://i.blackhat.com/USA-19/Wednesday/us-19-Tsai-Infiltrating-Corporate-Intranet-Like-NSA.pdf ExploitThird Party Advisory
https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44101 Third Party AdvisoryVendor Advisory
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2019-0010 Third Party Advisory
https://www.kb.cert.org/vuls/id/927237 Third Party AdvisoryUS Government Resource
http://packetstormsecurity.com/files/154376/Pulse-Secure-8.1R15.1-8.2-8.3-9.0-SSL-VPN-Remote-Code-Execution.html Third Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/155277/Pulse-Secure-VPN-Arbitrary-Command-Execution.html Third Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/162092/Pulse-Secure-VPN-Arbitrary-Command-Execution.html Broken LinkThird Party AdvisoryVDB Entry
http://www.securityfocus.com/bid/108073 Broken LinkThird Party AdvisoryVDB Entry
https://devco.re/blog/2019/09/02/attacking-ssl-vpn-part-3-the-golden-Pulse-Secure-ssl-vpn-rce-chain-with-Twitter-as-case ExploitThird Party Advisory
https://i.blackhat.com/USA-19/Wednesday/us-19-Tsai-Infiltrating-Corporate-Intranet-Like-NSA.pdf ExploitThird Party Advisory
https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44101 Third Party AdvisoryVendor Advisory
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2019-0010 Third Party Advisory
https://www.kb.cert.org/vuls/id/927237 Third Party AdvisoryUS Government Resource
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-11539 US Government Resource

Track CVE-2019-11539 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2021-22893Ivanti Pulse Connect Secure authentication bypass and use-after-free enabling RCEPulse Connect Secure 9.0R3/9.1R1 and higher contains an authentication bypass exposed through the Windows File Share Browser and Pulse Secure Collabo…KEVEPSS 47%analysed10.0CVE-2019-11510Pulse Connect Secure path traversal allows unauthenticated file readPulse Connect Secure versions 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4 contain a path traversal (CWE-22) flaw. An unauthentica…KEVEPSS 100%analysed9.8CVE-2025-22457Ivanti Connect Secure, Policy Secure and ZTA Gateways stack buffer overflow RCEA stack-based buffer overflow (CWE-121/CWE-787) in Ivanti Connect Secure, Policy Secure and ZTA Gateways allows a remote, unauthenticated attacker to…KEVEPSS 100%analysed9.1CVE-2024-21887Ivanti Connect Secure and Policy Secure web component command injectionIvanti Connect Secure and Policy Secure (9.x, 22.x) contain a command injection flaw (CWE-77) in web components. An authenticated administrator can s…KEVEPSS 100%analysed9.0CVE-2025-0282Ivanti Connect Secure stack buffer overflow enables unauthenticated RCEA stack-based buffer overflow (CWE-121/CWE-787) in Ivanti Connect Secure, Policy Secure and Neurons for ZTA gateways lets a remote, unauthenticated a…KEVEPSS 100%analysed8.8CVE-2021-22894Pulse Connect Secure buffer overflow allows root code executionPulse Connect Secure before 9.1R11.4 contains a buffer overflow reachable through a maliciously crafted meeting room. A remote authenticated attacker…KEVEPSS 41%analysed8.8CVE-2021-22899Pulse Connect Secure command injection via Windows Resource ProfilesPulse Connect Secure before 9.1R11.4 contains a command injection flaw (CWE-77) in the Windows Resource Profiles feature. An attacker who can authent…KEVEPSS 23%analysed8.2CVE-2024-21893Ivanti Connect Secure SAML SSRF allows unauthenticated resource accessThe SAML component of Ivanti Connect Secure, Policy Secure and Neurons for ZTA contains a server-side request forgery flaw that lets an attacker reac…KEVEPSS 100%analysed

Source: NIST National Vulnerability Database (record CVE-2019-11539), CISA KEV, FIRST EPSS (scores of 2026-09-16). This page is refreshed as NVD updates the record.