CVE-2019-11510: Pulse Secure Arbitrary File Read
A pre-authentication arbitrary file read vulnerability in Pulse Connect Secure SSL VPN appliances. An unauthenticated attacker can request arbitrary files from the appliance, including its session database, which caches plaintext usernames and passwords of users who logged in, effectively handing over VPN credentials without any exploitation skill required.
View the authoritative record on NVD ↗Affected software
- Pulse Connect Secure 8.2 before 8.2R12.1
- 8.3 before 8.3R7.1
- 9.0 before 9.0R3.4
How it's exploited
Send a crafted URI to an unauthenticated Pulse Connect Secure endpoint that traverses into internal application paths (a pattern such as /dana-na/../dana/html5acc/guacamole/../../../../../../etc/passwd) to read arbitrary files off the appliance, including cached session data containing plaintext credentials.
Severity
CVE-2019-11510 carries a CVSS 3.1 base score of 10.0, rated Critical. See how CVSS scoring works or score a vulnerability yourself with the free CVSS calculator.
Weakness type
CVE-2019-11510 is categorized under CWE-22, the general weakness pattern behind this specific vulnerability.
How TurboPentest tests for this
TurboPentest's automated black-box pentest actively probes for Path Traversal using OWASP ZAP and Nuclei and FFUF, with no source code required. Connecting a GitHub repo adds white-box confirmation from IntegSec's Opengrep SAST rule pack, which carries 9 dedicated rules for this weakness.
Tools: OWASP ZAP, Nuclei, FFUF
Remediation
Apply Pulse Secure's patched firmware, then rotate every credential and key that may have been cached on the appliance, since this flaw was mass exploited to harvest VPN logins long after patches shipped.
Frequently asked questions
What is CVE-2019-11510?
A pre-authentication arbitrary file read vulnerability in Pulse Connect Secure SSL VPN appliances. An unauthenticated attacker can request arbitrary files from the appliance, including its session database, which caches plaintext usernames and passwords of users who logged in, effectively handing over VPN credentials without any exploitation skill required.
How severe is CVE-2019-11510?
CVE-2019-11510 has a CVSS 3.1 base score of 10.0 out of 10, rated Critical.
What software is affected by CVE-2019-11510?
CVE-2019-11510 affects Pulse Connect Secure 8.2 before 8.2R12.1; 8.3 before 8.3R7.1; 9.0 before 9.0R3.4.
How do you fix CVE-2019-11510?
Apply Pulse Secure's patched firmware, then rotate every credential and key that may have been cached on the appliance, since this flaw was mass exploited to harvest VPN logins long after patches shipped.
Where is the authoritative record for CVE-2019-11510?
The National Vulnerability Database (NVD) publishes the authoritative record for CVE-2019-11510 at https://nvd.nist.gov/vuln/detail/CVE-2019-11510, including the current CVSS score, CWE mapping, and affected-configuration data.
Related CVEs
About this reference
These security references are maintained by IntegSec, an offensive-security firm whose team holds CISSP, OSCP, and OSCE certifications and has run thousands of penetration tests. Content is kept current as tools, standards, and attack techniques evolve.
Find known-vulnerable services before an attacker does
TurboPentest fingerprints every open port and web service, then matches detected versions against known CVEs automatically, from $99 per target.
Start a pentest