PublicCVE

CVE-2019-11510

CRITICAL9.9Path traversal
CISA KEVRansomwareExploitTrendingHigh EPSS

Description

In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthenticated remote attacker can send a specially crafted URI to perform an arbitrary file reading vulnerability .

CVSS breakdown

CVSS 3.0
Attack Complexity
Low
Attack Vector
Network
Availability
High
Confidentiality
High
Integrity
High
Privileges Required
Low
Scope
Changed
User Interaction
None
Updated 22m ago · 8 sources