CVE-2019-11510
KEV RANSOMWARECRITICAL 10.0EPSS 100.0%
In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthenticated remote attacker can send a specially crafted URI to perform an arbitrary file reading vulnerability .
- CVSS v3.1
- 10.0 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H - CVSS v3.0
- 9.9 CRITICAL
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H - CVSS v2.0
- 7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P - EPSS
- 100.00% chance of exploitation in the next 30 days, 100th percentile
- CISA KEV
- added 2021-11-03, used in ransomware campaigns
- Nuclei
- critical · CWE-22
- Published
- 2019-05-08
- Updated
- 2025-10-21
Proof-of-concept exploits (14)
- http://packetstormsecurity.com/files/154176/Pulse-Secure-SSL-VPN-8.1R15.1-8.2-8.3-9.0-Arb…
- https://devco.re/blog/2019/09/02/attacking-ssl-vpn-part-3-the-golden-Pulse-Secure-ssl-vpn…
- BishopFox/pwn-pulse133★ · 2020-01-15
- andripwn/pulse-exploit3★ · 2020-07-27
- aqhmal/pulsexploit9★ · 2020-04-25
- es0/CVE-2019-11510_poc5★ · 2019-08-27
- imjdl/CVE-2019-11510-poc50★ · 2019-08-26
- jas502n/CVE-2019-11510-152★ · 2019-08-27
- jason3e7/CVE-2019-115100★ · 2019-08-29
- nuc13us/Pulse0★ · 2026-02-06
- popyue/Pulse_exploit2★ · 2019-08-29
- projectzeroindia/CVE-2019-11510360★ · 2020-01-11
- pwn3z/CVE-2019-11510-PulseVPN1★ · 2020-11-05
- tanm-sys/secure-ssl-vpn-exploit-kit1★ · 2024-04-06
Nuclei templates (1)
Metasploit modules (1)
ExploitDB entries (1)
Exploit collections (2)
- chaitin/xray/blob/master/pocs/pulse-cve-2019-11510.yml
- zan8in/afrog/blob/main/pocs/afrog-pocs/CVE/2019/CVE-2019-11510.yaml