← Vulnerability feed

Vulnerability record · CVE-2019-11542 · published 26 April 2019

CVE-2019-11542: Pulse Secure SSL VPN admin interface stack buffer overflow

Ivanti · Connect Secure

Pulse Connect Secure and Pulse Policy Secure contain a stack buffer overflow (CWE-787) reachable through the admin web interface. An authenticated attacker can send a specially crafted message to trigger the overflow. Because these are SSL VPN gateways, a compromise can expose the corporate intranet.

7.2 CVSS 3.1 High EPSS 66% · top 0.8% CWE-787 · Out-of-bounds write
7.2CVSS 3.1 base score, v2 6.5
66%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
12References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1RX before 8.1R15.1 and Pulse Policy Secure version 9.0RX before 9.0R3.2, 5.4RX before 5.4R7.1, 5.3RX before 5.3R12.1, 5.2RX before 5.2R12.1, and 5.1RX before 5.1R15.1, an authenticated attacker (via the admin web interface) can send a specially crafted message resulting in a stack buffer overflow.

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

high priorityRequires admin credentials but offers high impact on an internet-facing SSL VPN gateway, with public exploit material and very high EPSS.

What it is

Pulse Connect Secure and Pulse Policy Secure contain a stack buffer overflow (CWE-787) reachable through the admin web interface. An authenticated attacker can send a specially crafted message to trigger the overflow. Because these are SSL VPN gateways, a compromise can expose the corporate intranet.

Impact

An authenticated admin-level attacker can corrupt stack memory, which can lead to code execution or a crash of the appliance. Successful exploitation gives control over the VPN gateway and a foothold into the internal network.

Attack surface

Reached over the network via the admin web interface (AV:N, PR:H, UI:N). The attacker must already hold valid administrative credentials; no user interaction is required.

Exploitation

Not listed in CISA KEV, but EPSS is 0.6559 (99.2nd percentile) and multiple references are tagged Exploit, including a Black Hat presentation and a public write-up describing a Pulse Secure RCE chain.

What to do

  • Upgrade Pulse Connect Secure to 9.0R3.4, 8.3R7.1, 8.2R12.1, or 8.1R15.1 (or later) and Pulse Policy Secure to 9.0R3.2, 5.4R7.1, 5.3R12.1, 5.2R12.1, or 5.1R15.1 (or later).
  • Restrict admin web interface access to trusted management networks and disable it from untrusted interfaces.
  • Enforce strong unique credentials and MFA for all administrative accounts to reduce the value of stolen admin sessions.
  • Monitor vendor advisory SA44101 and apply any subsequent patches or workarounds.

Detection

  • Alert on unexpected admin web interface logins, especially from new source IPs or outside maintenance windows.
  • Monitor appliance logs for crashes, restarts, or abnormal process termination on the VPN gateway.
  • Inspect admin interface HTTP requests for unusually long or malformed parameters that could indicate overflow attempts.
  • Correlate admin session activity with outbound connections from the appliance to internal hosts.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-11542 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2021-22893Ivanti Pulse Connect Secure authentication bypass and use-after-free enabling RCEPulse Connect Secure 9.0R3/9.1R1 and higher contains an authentication bypass exposed through the Windows File Share Browser and Pulse Secure Collabo…KEVEPSS 47%analysed10.0CVE-2019-11510Pulse Connect Secure path traversal allows unauthenticated file readPulse Connect Secure versions 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4 contain a path traversal (CWE-22) flaw. An unauthentica…KEVEPSS 100%analysed9.8CVE-2025-22457Ivanti Connect Secure, Policy Secure and ZTA Gateways stack buffer overflow RCEA stack-based buffer overflow (CWE-121/CWE-787) in Ivanti Connect Secure, Policy Secure and ZTA Gateways allows a remote, unauthenticated attacker to…KEVEPSS 100%analysed9.1CVE-2024-21887Ivanti Connect Secure and Policy Secure web component command injectionIvanti Connect Secure and Policy Secure (9.x, 22.x) contain a command injection flaw (CWE-77) in web components. An authenticated administrator can s…KEVEPSS 100%analysed9.0CVE-2025-0282Ivanti Connect Secure stack buffer overflow enables unauthenticated RCEA stack-based buffer overflow (CWE-121/CWE-787) in Ivanti Connect Secure, Policy Secure and Neurons for ZTA gateways lets a remote, unauthenticated a…KEVEPSS 100%analysed8.8CVE-2021-22894Pulse Connect Secure buffer overflow allows root code executionPulse Connect Secure before 9.1R11.4 contains a buffer overflow reachable through a maliciously crafted meeting room. A remote authenticated attacker…KEVEPSS 41%analysed8.8CVE-2021-22899Pulse Connect Secure command injection via Windows Resource ProfilesPulse Connect Secure before 9.1R11.4 contains a command injection flaw (CWE-77) in the Windows Resource Profiles feature. An attacker who can authent…KEVEPSS 23%analysed8.2CVE-2024-21893Ivanti Connect Secure SAML SSRF allows unauthenticated resource accessThe SAML component of Ivanti Connect Secure, Policy Secure and Neurons for ZTA contains a server-side request forgery flaw that lets an attacker reac…KEVEPSS 100%analysed

Source: NIST National Vulnerability Database (record CVE-2019-11542), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.