CVE-2019-11510 is a critical arbitrary file read vulnerability in Pulse Secure Pulse Connect Secure (PCS), also referenced in some sources alongside Pulse Policy Secure (PPS). The flaw is exploitable by an unauthenticated remote attacker over HTTPS by sending a specially crafted URI, enabling path traversal and arbitrary file disclosure from the appliance. Affected PCS versions include 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4; supporting content also lists vulnerable ranges such as 9.0R1–9.0R3.3, 8.3R1–8.3R7, and 8.2R1–8.2R12. The issue has been widely reported as a path traversal/arbitrary file read bug and has been actively exploited in the wild by both state-sponsored and criminal actors.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
4 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository contains a Bash script ('pwn-pulse.sh') that exploits the Pulse Connect Secure SSL VPN arbitrary file read vulnerability (CVE-2019-11510). The script is designed to automate the exploitation process by taking a target domain or IP address and attempting to download sensitive files from the VPN appliance using crafted directory traversal URLs. It then parses the downloaded files to extract private keys, usernames, admin details (including session cookies), and observed logins (including passwords). The script can also test session cookies to identify active sessions, which could be hijacked. All extracted information is compiled into a report file for each target. The repository includes a README with usage instructions and a LICENSE file. The main exploit logic resides in 'pwn-pulse.sh', which is the only code file. The attack vector is network-based, targeting accessible Pulse Connect Secure VPN appliances over HTTPS. The script is operational and provides real credential and session extraction capabilities, making it a practical tool for post-exploitation or red team activities.
This repository contains a Bash exploit script (CVE-2019-11510.sh) targeting Pulse Secure SSL VPN appliances vulnerable to CVE-2019-11510, a critical arbitrary file read vulnerability. The script allows an attacker to supply a single target or a list of targets (via a file) and attempts to exploit the directory traversal flaw to download sensitive files from the VPN appliance. It first checks for vulnerability by reading /etc/passwd, then proceeds to download /etc/hosts and internal database files (/data/runtime/mtmp/lmdb/dataa/data.mdb and /data/runtime/mtmp/lmdb/randomVal/data.mdb). The script extracts plaintext usernames, passwords, and session IDs from these files, saving the results in organized output directories per target. The repository also includes a README.md with usage instructions and references. The exploit is operational, automating the process of identifying vulnerable systems and extracting credentials and session information for further compromise.
This repository contains a single Python exploit script (pulsexploit.py) targeting Pulse Secure SSL VPN appliances vulnerable to CVE-2019-11510. The exploit automates the process of identifying vulnerable hosts by querying the Shodan API for devices exposing the '/dana/' path on port 443. For each discovered host, it attempts to exploit a path traversal vulnerability to read sensitive files from the system, including /etc/passwd, /etc/hosts, /etc/group, /etc/resolv.conf, and a session database file. The results are saved in an output directory for later analysis. The script is operational and requires a valid Shodan API key and internet access. The repository also includes a README with usage instructions, a requirements.txt for dependencies (shodan), and standard project files. The exploit is not part of a larger framework and is self-contained.
This repository contains a Python proof-of-concept exploit for CVE-2019-11510, a critical arbitrary file read vulnerability in Pulse Secure SSL VPN appliances. The main file, CVE-2019-11510.py, takes a target URL as input and attempts to exploit a directory traversal flaw to read sensitive files such as /etc/passwd and /etc/hosts from the remote system. If successful, the contents of these files are saved locally. The exploit works by crafting specific HTTP GET requests to vulnerable endpoints on the VPN device. The repository also includes a README.md with usage instructions and references. No payload for code execution is included; the exploit is limited to file read capabilities, making it a proof-of-concept for information disclosure. The attack vector is network-based, requiring access to the target's HTTPS interface.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
51 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Критическая уязвимость произвольного чтения файлов/path traversal в Pulse Connect Secure.
A known vulnerability in Pulse Secure Connect VPN that was used to gain initial access, steal credentials, and pivot into victim internal systems.
A known Pulse Secure VPN vulnerability explicitly referenced in forum activity as an entry point for compromising corporate networks.
An older Pulse Secure vulnerability cited as still being actively targeted in 2025 because it provides immediate remote access.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.