Vulnerability record · CVE-2019-11542 · published 26 April 2019
CVE-2019-11542: Pulse Secure SSL VPN admin interface stack buffer overflow
Ivanti · Connect Secure
Pulse Connect Secure and Pulse Policy Secure contain a stack buffer overflow (CWE-787) reachable through the admin web interface. An authenticated attacker can send a specially crafted message to trigger the overflow. Because these are SSL VPN gateways, a compromise can expose the corporate intranet.
Description
In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1RX before 8.1R15.1 and Pulse Policy Secure version 9.0RX before 9.0R3.2, 5.4RX before 5.4R7.1, 5.3RX before 5.3R12.1, 5.2RX before 5.2R12.1, and 5.1RX before 5.1R15.1, an authenticated attacker (via the admin web interface) can send a specially crafted message resulting in a stack buffer overflow.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityRequires admin credentials but offers high impact on an internet-facing SSL VPN gateway, with public exploit material and very high EPSS.
What it is
Pulse Connect Secure and Pulse Policy Secure contain a stack buffer overflow (CWE-787) reachable through the admin web interface. An authenticated attacker can send a specially crafted message to trigger the overflow. Because these are SSL VPN gateways, a compromise can expose the corporate intranet.
Impact
An authenticated admin-level attacker can corrupt stack memory, which can lead to code execution or a crash of the appliance. Successful exploitation gives control over the VPN gateway and a foothold into the internal network.
Attack surface
Reached over the network via the admin web interface (AV:N, PR:H, UI:N). The attacker must already hold valid administrative credentials; no user interaction is required.
Exploitation
Not listed in CISA KEV, but EPSS is 0.6559 (99.2nd percentile) and multiple references are tagged Exploit, including a Black Hat presentation and a public write-up describing a Pulse Secure RCE chain.
What to do
- Upgrade Pulse Connect Secure to 9.0R3.4, 8.3R7.1, 8.2R12.1, or 8.1R15.1 (or later) and Pulse Policy Secure to 9.0R3.2, 5.4R7.1, 5.3R12.1, 5.2R12.1, or 5.1R15.1 (or later).
- Restrict admin web interface access to trusted management networks and disable it from untrusted interfaces.
- Enforce strong unique credentials and MFA for all administrative accounts to reduce the value of stolen admin sessions.
- Monitor vendor advisory SA44101 and apply any subsequent patches or workarounds.
Detection
- Alert on unexpected admin web interface logins, especially from new source IPs or outside maintenance windows.
- Monitor appliance logs for crashes, restarts, or abnormal process termination on the VPN gateway.
- Inspect admin interface HTTP requests for unusually long or malformed parameters that could indicate overflow attempts.
- Correlate admin session activity with outbound connections from the appliance to internal hosts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2019-11542 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-11542), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.