Skip to main content
Mallory
HighCISA KEVExploited in the wildPublic exploit

Pulse Connect Secure / Pulse Policy Secure Admin Command Injection

IdentifiersCVE-2019-11539CWE-77

CVE-2019-11539 is a command injection vulnerability in the admin web interface of Pulse Secure Pulse Connect Secure and Pulse Policy Secure. The issue affects Pulse Connect Secure 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1RX before 8.1R15.1, as well as Pulse Policy Secure 9.0RX before 9.0R3.2, 5.4RX before 5.4R7.1, 5.3RX before 5.3R12.1, 5.2RX before 5.2R12.1, and 5.1RX before 5.1R15.1. According to the provided content, an authenticated attacker can use the administrative web interface to inject and execute commands on the appliance. The specific vulnerable function or parameter is not identified in the provided material.

Share:
For your environment

Are you exposed to this one?

Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.

ANALYST BRIEF

Impact, mitigation & remediation

What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.

Impact

What an attacker gets, and what they’ve been doing with it.

Successful exploitation allows execution of attacker-supplied commands on the affected appliance through the administrative interface. This can result in compromise of the VPN/security appliance, unauthorized administrative actions, further access into the protected environment, and use of the device as a foothold for persistence or follow-on intrusion activity. The supplied context also notes that exploitation of this flaw has been observed in real-world campaigns and that follow-on access inside private VPN networks may result.

Mitigation

If you can’t patch tonight, do this now.

No specific workaround for CVE-2019-11539 is provided in the supplied content. Practical mitigation, pending patching, is to restrict exposure of the admin web interface to trusted management networks only, enforce strong authentication and MFA for administrative access, minimize the number of administrative accounts, monitor for suspicious use of the admin interface, and isolate or remove vulnerable appliances from service until updated. The primary mitigation remains vendor patching/upgrading.

Remediation

Patch, then assume compromise.

Upgrade affected Pulse Connect Secure and Pulse Policy Secure systems to fixed releases. The provided content identifies the fixed versions as Pulse Connect Secure 9.0R3.4, 8.3R7.1, 8.2R12.1, and 8.1R15.1, and Pulse Policy Secure 9.0R3.2, 5.4R7.1, 5.3R12.1, 5.2R12.1, and 5.1R15.1, or later vendor-supported releases. If the appliance is end-of-life or end-of-engineering, replace it with a supported version or platform.
PUBLIC EXPLOITS

Exploits

1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).

VALID 1 / 2 TOTALView more in app
CVE-2019-11539MaturityPoCVerified exploit

This repository contains a single Python exploit script (CVE-2019-11539.py) targeting Pulse Secure VPN appliances vulnerable to CVE-2019-11539, a post-authentication remote code execution flaw. The exploit requires valid admin credentials and a web server hosting replacement SSH configuration and authorized_keys files. The script logs into the admin web interface, exploits a command injection vulnerability to execute arbitrary system commands, opens a firewall port, downloads and replaces SSH configuration files, and restarts the SSH daemon to enable root SSH access. The README provides detailed usage instructions, affected versions, and references. The exploit is operational and provides persistent root access if successful. No framework is used; the code is standalone Python. The main attack vector is network-based, targeting the HTTPS admin interface of the VPN appliance. Key endpoints and file paths are hardcoded or configurable in the script.

0xDezzyDisclosed Sep 4, 2019pythonnetwork
EXPOSURE SURFACE

Affected products & vendors

Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.

VendorProductType
IvantiConnect Secureapplication
IvantiPolicy Secureapplication
Pulse SecurePulse Policy Secureapplication

Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets are affected, which adversaries are exploiting it right now, which detections to deploy, and what to do tonight.
Exposure mapping

Query your assets running an affected version, and investigate the blast radius.

Threat actor evidence2

Every observed campaign linking this CVE to a named adversary.

Associated malware

Malware families riding this exploit, with evidence and IOCs.

Detection signatures1

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Vendor-by-vendor mapping

Cross-references every affected SKU, including bundled OEM variants.

Social activity

Community discussion across Reddit, Mastodon, and other social sources.