← KEV catalog
CISA known exploited vulnerability

CVE-2019-11539

Ivanti Pulse Connect Secure and Policy Secure Command Injection Vulnerability

SOURCE FACT

Ivanti · Pulse Connect Secure and Pulse Policy Secure

Ivanti Pulse Connect Secure and Policy Secure allows an authenticated attacker from the admin web interface to inject and execute commands.

Required action

Apply updates per vendor instructions.

CISA notes

https://nvd.nist.gov/vuln/detail/CVE-2019-11539

View source evidence →

CHECK YOUR OUTSIDE-IN INVENTORY

Could this product be present?