Skip to content
COOEY

EXPOSURES › CVE-2019-11510

CVE-2019-11510

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2019-11510 ↗
⌖ EXPLOITED IN THE WILD SHAME 72/100 ransomwareexploited-in-wildunpatched

Ivanti Pulse Connect Secure allowed unauthenticated attackers to read arbitrary files via a specially crafted URI, and was actively exploited in the wild, often linked to ransomware attacks.

A critical vulnerability in Ivanti Pulse Connect Secure enabled unauthenticated attackers to read files, potentially exposing sensitive data and system configurations. DIB organizations using this product face significant compliance risks under CMMC and NIST 800-171, and must immediately patch or mitigate the vulnerability. Failure to do so could lead to data breaches and regulatory penalties.

Shame score — The vulnerability's ease of exploitation and active exploitation by ransomware groups demonstrates a significant failure in secure coding practices and timely patching.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Ivanti Pulse Connect Secure contains an arbitrary file read vulnerability that allows an unauthenticated remote attacker with network access via HTTPS to send a specially crafted URI.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.60
Ivanti's CVE-2019-11510 arbitrary file read flaw was widely recognized as a critical, unauthenticated remote exploit risk, though the provided sources lack direct press commentary or vendor response d
cooey ↗ severe-fallout -0.60
NVD entry confirms critical unauthenticated remote file read flaw, implying severe risk but lacks press sentiment.
"Ivanti Pulse Connect Secure contains an arbitrary file read vulnerability that allows an unauthenticated remote attacker with network access via HTTPS to send a specially crafted URI."
sam.gov ↗ severe-fallout +0.00
No relevant security commentary; unrelated procurement page.
nypost.com ↗ severe-fallout +0.00
Irrelevant; unrelated article on sextortion.
CISA ↗ severe-fallout +0.00
No direct commentary; CISA catalog page lacks specific vendor sentiment.
www.cvefind.com ↗ severe-fallout +0.00
Irrelevant; CVE database homepage.
app.opencve.io ↗ severe-fallout +0.00
Irrelevant; unrelated CVE database page.
sec.cloudapps.cisco.com ↗ severe-fallout +0.00
Irrelevant; unrelated Cisco hardening advisory.
AFFECTED FEDRAMP PRODUCTS · 2
PRODUCTSTATUS
Ivanti Neurons for ITSM (Formerly Service Manager)
Ivanti
Authorized
Ivanti Neurons for MDM (Formerly MobileIron)
Ivanti
Authorized