Stack-based buffer overflow in Ivanti Policy Secure (formerly Pulse Policy Secure) and Ivanti Connect Secure (formerly Pulse Connect Secure) - CVE-2019-11542
Published: April 20, 2020
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error in Pulse Connect Secure and Pulse Policy Secure. A remote authenticated authenticated user (via the admin web interface) can send specially crafted message, trigger a stack-based buffer overflow and execute arbitrary code on the system.
Affected software
Ivanti Connect Secure (formerly Pulse Connect Secure)
How to mitigate CVE-2019-11542
Ivanti Connect Secure (formerly Pulse Connect Secure) - addressed in versions 8.1R15.1, 8.2R12.1, 8.3R7.1, 9.0R3.4