OS Command Injection in Ivanti Policy Secure (formerly Pulse Policy Secure) and Ivanti Connect Secure (formerly Pulse Connect Secure) - CVE-2019-11539

 

OS Command Injection in Ivanti Policy Secure (formerly Pulse Policy Secure) and Ivanti Connect Secure (formerly Pulse Connect Secure) - CVE-2019-11539

Published: April 20, 2020 / Updated: February 20, 2022


Vulnerability identifier: #VU27039
CSH Severity: Medium
CVSS v4: 7.5 [CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-11539
CWE-ID: CWE-78
Exploitation vector: Remote access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary shell commands on the target system.

The vulnerability exists due to improper input validation in admin web interface of Pulse Connect Secure and Pulse Policy Secure. A remote authenticated user can execute arbitrary OS commands.


Affected software

Ivanti Policy Secure (formerly Pulse Policy Secure)
Ivanti Connect Secure (formerly Pulse Connect Secure)

How to mitigate CVE-2019-11539

Install updates from vendor's website.

Ivanti Policy Secure (formerly Pulse Policy Secure) - addressed in versions 5.1R15.1, 5.2R12.1, 5.3R12.1, 5.4R7.1, 9.0R3.2
Ivanti Connect Secure (formerly Pulse Connect Secure) - addressed in versions 8.1R15.1, 8.2R12.1, 8.3R7.1, 9.0R3.4

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins