LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2019-11539: Ivanti Pulse Connect Secure and Policy Secure Command Injection Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 3, 2021
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
May 3, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2019-11539 to its Known Exploited Vulnerabilities catalog on Nov 3, 2021, with a federal patch deadline of May 3, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

Ivanti Pulse Connect Secure and Policy Secure allows an authenticated attacker from the admin web interface to inject and execute commands.

CVE-2019-11539 is a command injection vulnerability in Ivanti Pulse Connect Secure and Pulse Policy Secure. An authenticated attacker who can reach the admin web interface may inject and execute operating-system commands on the appliance. Because these products commonly sit at the edge as VPN and policy gateways, successful abuse can give an attacker a foothold on a high-value network device. CISA notes that this vulnerability has been used in ransomware operations, so organizations still running affected systems should treat remediation as a priority and confirm all details against the vendor advisory.

How it works

The weakness is classified as CWE-78 (OS Command Injection). In products of this class, user-supplied input that reaches a shell or system call is not adequately sanitized. When an attacker already possesses valid administrative credentials for the web management interface, they can craft input that the appliance interprets as commands rather than data. Those commands then run with the privileges of the underlying service. Public detail beyond the CISA summary is limited; exact injection points, request formats, and any prerequisites must be confirmed against the vendor advisory. No exploit code or step-by-step mechanics are provided here.

Am I affected? How to find it in your systems

Pulse Connect Secure and Pulse Policy Secure typically run as dedicated appliances or virtual appliances that terminate remote-access VPN sessions and enforce access policy. Inventory every instance by:

Because the attack requires authentication to the admin interface, also identify every account that has administrative rights and whether that interface is reachable from untrusted networks. Log sources worth examining include admin-interface access logs, authentication successes/failures, and any process-execution or command-history logs the appliance can export. Unexpected command activity or new administrative sessions originating from unusual source addresses may indicate abuse; correlate these with the vendor’s guidance on forensic indicators.

How to remediate

The primary action is to apply the updates published by the vendor, exactly as directed in the advisory and as required by CISA (“Apply updates per vendor instructions”). After patching:

These steps harden the device against both this specific command-injection class and similar authenticated management-plane attacks.

If you can't patch immediately

Until the vendor update can be installed, reduce exposure with compensating controls:

These measures do not eliminate the vulnerability but shrink the window an attacker has to reach and exploit it.

If your data may have been exposed

Actively exploited vulnerabilities, especially those with confirmed ransomware use, frequently lead to broader compromise and data theft. If you have reason to believe an appliance was accessed by an unauthorized party, follow your incident-response plan: isolate the device, preserve logs, and assess downstream systems that authenticated through it. As a quick additional check, you can run a free exposure scan of your email addresses against known breach data sets to see whether credentials or personal information have already appeared in public dumps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedIvanti · Pulse Connect Secure and Pulse Policy Secure
WeaknessCWE-78
Added to CISA KEVNov 3, 2021
Federal patch deadlineMay 3, 2022
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities