LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2019-11510: Ivanti Pulse Connect Secure Arbitrary File Read Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 3, 2021
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
May 3, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2019-11510 to its Known Exploited Vulnerabilities catalog on Nov 3, 2021, with a federal patch deadline of May 3, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

Ivanti Pulse Connect Secure contains an arbitrary file read vulnerability that allows an unauthenticated remote attacker with network access via HTTPS to send a specially crafted URI.

CVE-2019-11510 is an arbitrary file read vulnerability in Ivanti Pulse Connect Secure. An unauthenticated remote attacker with network access via HTTPS can send a specially crafted URI to read files on the device. This matters because the product is commonly deployed as a remote-access VPN gateway; successful abuse can expose configuration, credentials, or other sensitive data and has been tied to ransomware activity.

Defenders should treat internet-facing instances as high priority until they confirm the vendor fix is applied and residual exposure is checked.

How it works

The weakness is classified as CWE-22 (path traversal / improper limitation of a pathname). In this class of flaw, the application fails to adequately sanitize user-supplied path elements in a request. An attacker who can reach the HTTPS interface crafts a URI that causes the appliance to return the contents of files outside the intended web root or document store.

Because the CISA summary states the attack requires no authentication and only network access over HTTPS, the practical abuse path is straightforward: the attacker targets the exposed management or user portal endpoint, supplies the malicious URI, and retrieves file contents. Exact request format and which files are reachable must be confirmed against the vendor advisory; do not rely on third-party write-ups alone for detection logic.

Am I affected? How to find it in your systems

Ivanti Pulse Connect Secure (formerly Pulse Secure) typically runs as a hardware or virtual appliance providing SSL VPN and remote access. It is often placed at the network edge and reachable from the internet on TCP 443.

How to remediate

Patch first. Apply the updates published by Ivanti for Pulse Connect Secure exactly as described in the vendor advisory and follow the CISA required action: apply updates per vendor instructions. After patching, verify the new build is running and re-check that the previously vulnerable URI patterns no longer return file contents.

Additional hardening for this class of issue:

If you can't patch immediately

Until the vendor update can be installed, reduce risk with compensating controls:

These measures lower likelihood and impact but do not replace the official patch.

If your data may have been exposed

This vulnerability has been used in ransomware campaigns. If your Pulse Connect Secure instance was internet-facing and unpatched during the period of known exploitation, assume sensitive files may have been read and treat the incident as a potential breach. Follow your incident-response process: isolate affected systems, preserve logs, rotate credentials and certificates that could have been obtained, and assess downstream impact on connected identity and network resources. You can run a free exposure scan of your email addresses against known breach data sets to check whether associated accounts appear in public breach corpora while you complete containment and recovery.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedIvanti · Pulse Connect Secure
WeaknessCWE-22
Added to CISA KEVNov 3, 2021
Federal patch deadlineMay 3, 2022
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities