CVE-2019-11539 is an authenticated operating-system command injection vulnerability in the administrative web interface of Pulse Connect Secure and Pulse Policy Secure. The affected diagnostic functionality passes an administrator-controlled options parameter to tcpdump. Insufficient command parsing and filtering in the DSSAFE.pm restrictions can be bypassed, allowing injected commands to execute on the appliance. Affected Pulse Connect Secure releases are 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1RX before 8.1R15.1. Affected Pulse Policy Secure releases are 9.0RX before 9.0R3.2, 5.4RX before 5.4R7.1, 5.3RX before 5.3R12.1, 5.2RX before 5.2R12.1, and 5.1RX before 5.1R15.1.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository contains a single Metasploit module (modules/exploits/linux/http/pulse_secure_cmd_exec.rb) that exploits CVE-2019-11539, a post-authentication command injection vulnerability in Pulse Secure VPN servers. The exploit requires a valid administrator session ID (SID) and targets the /dana-admin/diag/diag.cgi endpoint to inject and execute arbitrary commands as root, bypassing application whitelisting using the env(1) command. The module supports both direct command execution and staged payload delivery (e.g., Meterpreter reverse shell) using curl. The exploit is operational and can be used to gain full control of vulnerable Pulse Secure VPN appliances. The code is written in Ruby and is designed to be run within the Metasploit Framework. The only file present is the exploit module itself, which is well-structured and leverages Metasploit's HTTP client and command stager mixins. No detection or auxiliary scripts are present in this repository.
This repository contains a single Python exploit script (CVE-2019-11539.py) targeting Pulse Secure VPN appliances vulnerable to CVE-2019-11539, a post-authentication remote code execution flaw. The exploit requires valid admin credentials and a web server hosting replacement SSH configuration and authorized_keys files. The script logs into the admin web interface, exploits a command injection vulnerability to execute arbitrary system commands, opens a firewall port, downloads and replaces SSH configuration files, and restarts the SSH daemon to enable root SSH access. The README provides detailed usage instructions, affected versions, and references. The exploit is operational and provides persistent root access if successful. No framework is used; the code is standalone Python. The main attack vector is network-based, targeting the HTTPS admin interface of the VPN appliance. Key endpoints and file paths are hardcoded or configurable in the script.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An admin command injection vulnerability affecting Pulse Connect Secure / Policy Secure.
A command injection vulnerability in Ivanti Pulse Connect Secure and Policy Secure listed as part of historically targeted vulnerabilities.
A high-severity authenticated command injection vulnerability in the admin web interface of Pulse Connect Secure and Pulse Policy Secure.
A post-authentication administrator command-injection flaw in the Pulse Secure management interface. Attackers can bypass command-line restrictions and write executable Perl content to the template cache, resulting in remote command execution.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.