CVE-2019-11508

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
08/05/2019
Last modified:
27/02/2024

Description

In Pulse Secure Pulse Connect Secure (PCS) before 8.1R15.1, 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an authenticated attacker (via the admin web interface) can exploit Directory Traversal to execute arbitrary code on the appliance.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ivanti:connect_secure:7.1:*:*:*:*:*:*:*
cpe:2.3:a:ivanti:connect_secure:7.1:r1.0:*:*:*:*:*:*
cpe:2.3:a:ivanti:connect_secure:7.1:r1.1:*:*:*:*:*:*
cpe:2.3:a:ivanti:connect_secure:7.1:r10.0:*:*:*:*:*:*
cpe:2.3:a:ivanti:connect_secure:7.1:r11.0:*:*:*:*:*:*
cpe:2.3:a:ivanti:connect_secure:7.1:r12.0:*:*:*:*:*:*
cpe:2.3:a:ivanti:connect_secure:7.1:r13.0:*:*:*:*:*:*
cpe:2.3:a:ivanti:connect_secure:7.1:r14.0:*:*:*:*:*:*
cpe:2.3:a:ivanti:connect_secure:7.1:r15.0:*:*:*:*:*:*
cpe:2.3:a:ivanti:connect_secure:7.1:r16.0:*:*:*:*:*:*
cpe:2.3:a:ivanti:connect_secure:7.1:r17.0:*:*:*:*:*:*
cpe:2.3:a:ivanti:connect_secure:7.1:r18.0:*:*:*:*:*:*
cpe:2.3:a:ivanti:connect_secure:7.1:r19.0:*:*:*:*:*:*
cpe:2.3:a:ivanti:connect_secure:7.1:r19.1:*:*:*:*:*:*
cpe:2.3:a:ivanti:connect_secure:7.1:r2.0:*:*:*:*:*:*