Ivanti Pulse Connect Secure Arbitrary File Read Vulnerability
n/a — n/a
In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthenticated remote attacker can send a specially crafted URI to perform an arbitrary file reading vulnerability .
10.0
100.0%
Vector breakdown
- Attack vector
- Network
- Attack complexity
- Low
- Privileges required
- None
- User interaction
- None
- Scope
- Changed
- Confidentiality
- High
- Integrity
- High
- Availability
- High
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- Published
- May 8, 2019
- Modified
- Jun 17, 2026
- Added to KEV
- Nov 3, 2021
- Federal patch due
- May 3, 2022
CISA required action
Apply updates per vendor instructions.
Weakness classification
Affected packages
Proof-of-concept & exploitation references
8 foundWeaponization
Public repositories whose name or description references CVE-2019-11510, found via a live GitHub search at request time. These are community-sourced signals, not a verified working exploit - cross-check each one before relying on it, and treat higher star counts and recent activity as (weak) corroboration, not proof.
- projectzeroindia/CVE-2019-11510★ 360
Exploit for Arbitrary File Read on Pulse Secure SSL VPN (CVE-2019-11510)
updated Jul 29, 2026
- BishopFox/pwn-pulse★ 133
Exploit for Pulse Connect Secure SSL VPN arbitrary file read vulnerability (CVE-2019-11510)
updated Jul 29, 2026
- jas502n/CVE-2019-11510-1★ 52
SSL VPN Rce
updated Mar 31, 2026
- imjdl/CVE-2019-11510-poc★ 50
Pulse Secure SSL VPN pre-auth file reading
updated Aug 12, 2024
- cisagov/check-your-pulse★ 28
This utility can help determine if indicators of compromise (IOCs) exist in the log files of a Pulse Secure VPN Appliance for CVE-2019-11510.
updated Aug 12, 2024
- r00tpgp/http-pulse_ssl_vpn.nse★ 18
Nmap NSE script to detect Pulse Secure SSL VPN file disclosure CVE-2019-11510
updated Aug 12, 2024
- aqhmal/pulsexploit★ 9
Automated script for Pulse Secure SSL VPN exploit (CVE-2019-11510) using hosts retrieved from Shodan API. You must have a Shodan account to use this script.
updated Jul 1, 2025
- es0/CVE-2019-11510_poc★ 5
PoC for CVE-2019-11510 | Pulse Secure 8.1R15.1/8.2/8.3/9.0 SSL VPN - Arbitrary File Disclosure vulnerability
updated Aug 12, 2024
References
How this class of flaw gets exploited
Frequently asked questions
What is CVE-2019-11510?
In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthenticated remote attacker can send a specially crafted URI to perform an arbitrary file reading vulnerability .
How severe is CVE-2019-11510?
CVE-2019-11510 has a CVSS base score of 10.0 out of 10 (CVSS 3.1).
Is CVE-2019-11510 actively exploited in the wild?
Yes. CVE-2019-11510 is listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added Nov 3, 2021, meaning CISA has confirmed evidence of active exploitation. It is also flagged as used in ransomware campaigns.
What is the EPSS score for CVE-2019-11510?
100.0% - meaning FIRST.org's EPSS model estimates a 100.0% probability this vulnerability will be exploited in the wild within 30 days (100% percentile among all scored CVEs).
Is there exploit tooling available for CVE-2019-11510?
Yes - a public Nuclei template referencing CVE-2019-11510 exist in public repositories we checked. We also found 8 public GitHub repositories referencing this CVE.
What type of vulnerability is CVE-2019-11510?
CVE-2019-11510 is classified under CWE-22 (CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')).
Cross-checked against
Impactr finds and proves whether CVE-2019-11510 - or flaws like it - are actually reachable in your own web apps and APIs, with a reproducible exploit as evidence.
Join the waitlist