OS Command Injection in Ivanti Policy Secure (formerly Pulse Policy Secure) and Ivanti Connect Secure (formerly Pulse Connect Secure) - CVE-2019-11539
Published: April 20, 2020 / Updated: February 20, 2022
Vulnerability identifier: #VU27039
CSH Severity: Medium
CVSS v4: 7.5 [CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-11539
CWE-ID: CWE-78
Exploitation vector: Remote access
Exploit availability:
The vulnerability is being exploited in the wild
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary shell commands on the target system.
The vulnerability exists due to improper input validation in admin web interface of Pulse Connect Secure and Pulse Policy Secure. A remote authenticated user can execute arbitrary OS commands.
Affected software
Ivanti Policy Secure (formerly Pulse Policy Secure)
Ivanti Connect Secure (formerly Pulse Connect Secure)
Ivanti Connect Secure (formerly Pulse Connect Secure)
How to mitigate CVE-2019-11539
Install updates from vendor's website.
Ivanti Policy Secure (formerly Pulse Policy Secure) - addressed in versions 5.1R15.1, 5.2R12.1, 5.3R12.1, 5.4R7.1, 9.0R3.2
Ivanti Connect Secure (formerly Pulse Connect Secure) - addressed in versions 8.1R15.1, 8.2R12.1, 8.3R7.1, 9.0R3.4
Ivanti Connect Secure (formerly Pulse Connect Secure) - addressed in versions 8.1R15.1, 8.2R12.1, 8.3R7.1, 9.0R3.4