CVE-2019-11510
CRITICAL KEV RANSOMWARE NUCLEIPulse Secure PCS <9.0R3.4 - Info Disclosure
Title source: llmExploitation Summary
CVE-2019-11510 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added November 3, 2021, with confirmed use in ransomware campaigns.
EIP tracks 15 public exploits from researchers including Alyssa Herrera, projectzeroindia, BishopFox, including a Metasploit module auxiliary/gather/pulse_secure_file_disclosure.
A Nuclei detection template is also available.
AI-analyzed exploit summary This Metasploit auxiliary module exploits CVE-2019-11510, a file disclosure vulnerability in Pulse Secure SSL VPN. It sends a crafted HTTP request to leak system files (e.g., /etc/passwd) via directory traversal.
Description
In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthenticated remote attacker can send a specially crafted URI to perform an arbitrary file reading vulnerability .
Exploits (15)
This Metasploit auxiliary module exploits CVE-2019-11510, a file disclosure vulnerability in Pulse Secure SSL VPN. It sends a crafted HTTP request to leak system files (e.g., /etc/passwd) via directory traversal.
This repository contains a functional exploit script for CVE-2019-11510, which targets an arbitrary file read vulnerability in Pulse Secure SSL VPN. The script automates the extraction of sensitive files like /etc/passwd, /etc/hosts, and credential databases, demonstrating the vulnerability's impact.
This repository contains a functional exploit script for CVE-2019-11510, an arbitrary file read vulnerability in Pulse Connect Secure SSL VPN. The script automates the extraction of sensitive data such as private keys, usernames, session cookies, and passwords by leveraging the vulnerability to download and parse configuration files.
The repository contains a functional Python script that exploits CVE-2019-11510, a directory traversal vulnerability in Pulse Secure SSL VPN, allowing arbitrary file read. The script constructs malicious URLs to access sensitive files like /etc/passwd and /etc/hosts.
This repository contains a functional exploit PoC for CVE-2019-11510, a pre-authentication arbitrary file read vulnerability in Pulse Secure SSL VPN. The exploit leverages path traversal to read sensitive files like /etc/passwd and /etc/hosts.
This repository contains a Python-based tool for detecting the Pulse Secure VPN vulnerability (CVE-2019-11510) by checking for indicators of compromise. It does not include exploit code but provides a framework for scanning and reporting potential vulnerabilities.
This is an NSE script for Nmap that detects the Pulse Secure SSL VPN file disclosure vulnerability (CVE-2019-11510) by sending crafted HTTP requests to read /etc/passwd as a proof of concept. It does not exploit the vulnerability but scans for its presence.
This repository contains a functional exploit for CVE-2019-11510, an arbitrary file read vulnerability in Pulse Secure SSL VPN. The script automates the exploitation process by querying Shodan for potential targets and attempting to read sensitive files like /etc/passwd.
This repository contains a functional Python script that exploits CVE-2019-11510, an arbitrary file disclosure vulnerability in Pulse Secure SSL VPN. The script sends a crafted HTTP request to read sensitive files like /etc/passwd via path traversal.
The repository lists multiple CVEs and tools but contains no actual exploit code or technical details. It appears to be a collection of references without functional PoCs, likely serving as a lure for further engagement.
The repository contains a functional exploit script for CVE-2019-11510, an arbitrary file read vulnerability in Pulse Secure Pulse Connect Secure. The script checks for vulnerability by attempting to read /etc/passwd via a crafted URI path traversal.
This repository contains a functional exploit for CVE-2019-11510, an arbitrary file read vulnerability in Pulse Secure SSL VPN. The script automates the exploitation process by querying Shodan for potential targets and attempting to read sensitive files like /etc/passwd.
This repository contains a Python script that uses the Shodan API to scan for IP addresses vulnerable to CVE-2019-11510, a Pulse Secure arbitrary file read vulnerability. It checks for the presence of a specific endpoint and logs vulnerable hosts to a file.
The repository contains only a README.md file with no actual exploit code or technical details. It appears to be a placeholder or incomplete repository.
This Metasploit module exploits a pre-authentication directory traversal vulnerability in Pulse Secure VPN (CVE-2019-11510) to disclose arbitrary files, including credentials and session IDs. It supports both automatic and manual modes for file extraction.
Nuclei Templates (1)
http.html:"welcome.cgi?p=logo" || http.title:"ivanti connect secure"
body="welcome.cgi?p=logo" || title="ivanti connect secure"
References (12)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H