EXPOSURES › CVE-2019-11510
CVE-2019-11510
CRITICAL ⌖ ON CISA KEV · EXPLOITEDIvanti Pulse Connect Secure allowed unauthenticated attackers to read arbitrary files via a specially crafted URI, and was actively exploited in the wild, often linked to ransomware attacks.
A critical vulnerability in Ivanti Pulse Connect Secure enabled unauthenticated attackers to read files, potentially exposing sensitive data and system configurations. DIB organizations using this product face significant compliance risks under CMMC and NIST 800-171, and must immediately patch or mitigate the vulnerability. Failure to do so could lead to data breaches and regulatory penalties.
Shame score — The vulnerability's ease of exploitation and active exploitation by ransomware groups demonstrates a significant failure in secure coding practices and timely patching.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Ivanti Pulse Connect Secure contains an arbitrary file read vulnerability that allows an unauthenticated remote attacker with network access via HTTPS to send a specially crafted URI.
"Ivanti Pulse Connect Secure contains an arbitrary file read vulnerability that allows an unauthenticated remote attacker with network access via HTTPS to send a specially crafted URI."
| PRODUCT | STATUS |
|---|---|
| Ivanti Neurons for ITSM (Formerly Service Manager) Ivanti |
Authorized |
| Ivanti Neurons for MDM (Formerly MobileIron) Ivanti |
Authorized |