Skip to content
COOEY

EXPOSURES › CVE-2019-11539

CVE-2019-11539

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2019-11539 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 ransomwarerceexploited-in-wildunpatched

Authenticated admins of Ivanti Pulse Connect Secure/Policy Secure could inject and execute commands via the web interface, actively exploited in ransomware attacks.

A command injection vulnerability (CVE-2019-11539) in Ivanti Pulse Connect Secure and Policy Secure allowed authenticated administrators to execute arbitrary commands, which was actively exploited, including in ransomware campaigns. DIB organizations using these products face significant risk of compromise and non-compliance with CMMC/NIST 800-171; immediate patching and incident response are critical.

Shame score — The vulnerability's exploitation in ransomware attacks, coupled with the ease of execution via the admin interface, demonstrates a significant failure in secure coding practices and a high degree of negligence.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Ivanti Pulse Connect Secure and Policy Secure allows an authenticated attacker from the admin web interface to inject and execute commands.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.60
Ivanti faced severe criticism for a critical command injection flaw in its admin interface, allowing authenticated attackers to execute arbitrary commands, which was widely flagged as a high-severity
cooey ↗ severe-fallout -0.80
Severe vulnerability in admin interface allowing command execution, widely condemned as a critical flaw requiring urgent patching.
"Ivanti Pulse Connect Secure and Policy Secure allows an authenticated attacker from the admin web interface to inject and execute commands."
AFFECTED FEDRAMP PRODUCTS · 2
PRODUCTSTATUS
Ivanti Neurons for ITSM (Formerly Service Manager)
Ivanti
Authorized
Ivanti Neurons for MDM (Formerly MobileIron)
Ivanti
Authorized