Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2019-11510

KEV · Ransomware EPSS 94.46% · P100
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2019-11510

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthenticated remote attacker can send a specially crafted URI to perform an arbitrary file reading vulnerability .
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Pulse Secure Pulse Connect Secure 路径遍历漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Pulse Secure Pulse Connect Secure(又名PCS,前称Juniper Junos Pulse)是美国Pulse Secure公司的一套SSL VPN解决方案。 Pulse Secure PCS 9.0RX版本、8.3RX版本和8.2RX版本中存在路径遍历漏洞。该漏洞源于网络系统或产品未能正确地过滤资源或文件路径中的特殊元素。攻击者可利用该漏洞访问受限目录之外的位置。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Shenlong Deep Dive — AI Deep Analysis

10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2019-11510

#POC DescriptionSource LinkShenlong Link
1Exploit for Arbitrary File Read on Pulse Secure SSL VPN (CVE-2019-11510)https://github.com/projectzeroindia/CVE-2019-11510POC Details
2Pulse Secure VPN CVE-2019-11510https://github.com/nuc13us/PulsePOC Details
3Pulse Secure SSL VPN pre-auth file readinghttps://github.com/imjdl/CVE-2019-11510-pocPOC Details
4PoC for CVE-2019-11510 | Pulse Secure 8.1R15.1/8.2/8.3/9.0 SSL VPN - Arbitrary File Disclosure vulnerabilityhttps://github.com/es0/CVE-2019-11510_pocPOC Details
5Nmap NSE script to detect Pulse Secure SSL VPN file disclosure CVE-2019-11510https://github.com/r00tpgp/http-pulse_ssl_vpn.nsePOC Details
6SSL VPN Rcehttps://github.com/jas502n/CVE-2019-11510-1POC Details
7Nonehttps://github.com/jason3e7/CVE-2019-11510POC Details
8Exploit for Pulse Connect Secure SSL VPN arbitrary file read vulnerability (CVE-2019-11510)https://github.com/BishopFox/pwn-pulsePOC Details
9Automated script for Pulse Secure SSL VPN exploit (CVE-2019-11510) using hosts retrieved from Shodan API. You must have a Shodan account to use this script.https://github.com/aqhmal/pulsexploitPOC Details
10This utility can help determine if indicators of compromise (IOCs) exist in the log files of a Pulse Secure VPN Appliance for CVE-2019-11510.https://github.com/cisagov/check-your-pulsePOC Details
11Pulse Secure SSL VPN exploit (CVE-2019-11510) using hosts retrieved from Shodan API.https://github.com/andripwn/pulse-exploitPOC Details
12Nonehttps://github.com/pwn3z/CVE-2019-11510-PulseVPNPOC Details
13cve-2019-11510, cve-2019-19781, cve-2020-5902,               cve-2021-1497, cve-2021-20090, cve-2021-22006, cve-2021-22205, cve-2021-26084, cve-2021-26855, cve-2021-26857, cve-2021–26857, cve-2021–26858, cve-2021–26865https://github.com/34zY/APT-BackpackPOC Details
14Nonehttps://github.com/0xab01/-CVE-2019-11510-ExploitPOC Details
15Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4 all contain an arbitrary file reading vulnerability that could allow unauthenticated remote attackers to send a specially crafted URI to gain improper access.https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2019/CVE-2019-11510.yamlPOC Details
16Nonehttps://github.com/chaitin/xray-plugins/blob/main/poc/manual/pulse-cve-2019-11510.ymlPOC Details
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2019-11510

登录查看更多情报信息。

Same Patch Batch · n/a · 2019-05-08 · 37 CVEs total

CVE-2019-11818Alkacon Software OpenCMS New User模块跨站脚本漏洞
CVE-2019-2046Android 输入验证错误漏洞
CVE-2019-2045Android 缓冲区错误漏洞
CVE-2019-2044Android 缓冲区错误漏洞
CVE-2019-2043Android 权限许可和访问控制问题漏洞
CVE-2019-11550Citrix Systems SD-WAN和Citrix Systems NetScaler SD-WAN 信任管理问题漏洞
CVE-2019-11561多款Chuango产品访问控制错误漏洞
CVE-2019-11564Humhub 跨站脚本漏洞
CVE-2019-11819Alkacon Software OpenCMS New User模块注入漏洞
CVE-2019-2047Android 缓冲区错误漏洞
CVE-2019-11642OneShield Policy框架注入漏洞
CVE-2019-11643OneShield Policy框架跨站脚本漏洞
CVE-2019-11815Linux kernel 竞争条件问题漏洞
CVE-2019-8349HTMLy 跨站脚本漏洞
CVE-2019-8387Master IP CAM 01 命令注入漏洞
CVE-2019-11814MISP 跨站脚本漏洞
CVE-2019-11813MISP 跨站脚本漏洞
CVE-2019-11812MISP 跨站脚本漏洞
CVE-2019-11507Pulse Secure Pulse Connect Secure 跨站脚本漏洞
CVE-2019-9698Symantec AV Engine 权限许可和访问控制问题漏洞

Showing top 20 of 37 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2019-11510

No comments yet


Leave a comment