CISA Known Exploited Vulnerability

CVE-2019-11510 Ransomware

Ivanti · Pulse Connect Secure

Ivanti Pulse Connect Secure Arbitrary File Read Vulnerability

Date added
BOD 22-01 due date
CWE CWE-22
Ransomware Known

CISA description

Ivanti Pulse Connect Secure contains an arbitrary file read vulnerability that allows an unauthenticated remote attacker with network access via HTTPS to send a specially crafted URI.

Required action

Apply updates per vendor instructions.

Notes & references