# CVE-2019-11510 — Ivanti Connect Secure 8.2

**CISA KEV** · **Ransomware**

> As of 2025-10-21, CVE-2019-11510 is a CRITICAL-severity vulnerability in Ivanti Connect Secure 8.2, CVSS v3.1 9.9, EPSS 99.9% (99.9th percentile). It is listed in the CISA Known Exploited Vulnerabilities catalog (added 2021-11-03), with a US federal remediation deadline of 2022-05-03, and CISA links it to known ransomware campaigns. Threadlinqs Intelligence links 1 tracked threat campaign to CVE-2019-11510, most recently “Sen. Wyden Urges Binding Federal Mandate to Purge Internet-Facing Legacy VPNs for Zero-Trust Remote Access”.

**Last updated:** 2025-10-21

## What is CVE-2019-11510?

In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthenticated remote attacker can send a specially crafted URI to perform an arbitrary file reading vulnerability .

The record classifies CVE-2019-11510 under weakness class [CWE-22](https://intel.threadlinqs.com/cwe/CWE-22). Its CVSS v3 base vector states that the flaw is reachable remotely over the network, needs low-privilege credentials, needs no user interaction, and has high impact on confidentiality, integrity, availability. 30 affected-product entries are recorded, across 1 vendor, listed below. The identifier was first published 2707 days ago.

## Severity and exploitation probability

- **CVSS v3.1 base score:** 9.9 — CRITICAL (`CVSS:3.0/AC:L/AV:N/A:H/C:H/I:H/PR:L/S:C/UI:N`)
- **EPSS (FIRST):** 99.9% probability of exploitation in the next 30 days, higher than 99.9% of all scored CVEs
- **CISA KEV:** Listed since 2021-11-03, federal remediation deadline 2022-05-03 — used in known ransomware campaigns
- **Threadlinqs priority:** 10/10 — CISA lists it as used in ransomware, which Threadlinqs scores at the maximum
- **Published:** 2019-05-08, last modified 2025-10-21

## Is CVE-2019-11510 being exploited?

CISA added CVE-2019-11510 to the Known Exploited Vulnerabilities catalog on 2021-11-03, which means the agency holds evidence of exploitation in the wild; US federal civilian agencies had to remediate it by 2022-05-03 under BOD 22-01. CISA flags the vulnerability as one used in known ransomware campaigns. Weaponised exploit code for CVE-2019-11510 is publicly available. 11 public proof-of-concept repositories are tracked for this identifier. A ProjectDiscovery Nuclei detection template exists (`http/cves/2019/CVE-2019-11510.yaml`). It currently carries a trending score of 45 in the Threadlinqs vulnerability feed.

- [projectzeroindia/CVE-2019-11510](https://github.com/projectzeroindia/CVE-2019-11510) (github)
- [BishopFox/pwn-pulse](https://github.com/BishopFox/pwn-pulse) (github)
- [jas502n/CVE-2019-11510-1](https://github.com/jas502n/CVE-2019-11510-1) (github)
- [imjdl/CVE-2019-11510-poc](https://github.com/imjdl/CVE-2019-11510-poc) (github)
- [cisagov/check-your-pulse](https://github.com/cisagov/check-your-pulse) (github)
- [r00tpgp/http-pulse_ssl_vpn.nse](https://github.com/r00tpgp/http-pulse_ssl_vpn.nse) (github)
- [aqhmal/pulsexploit](https://github.com/aqhmal/pulsexploit) (github)
- [es0/CVE-2019-11510_poc](https://github.com/es0/CVE-2019-11510_poc) (github)

## Affected products and versions

- [Ivanti](https://intel.threadlinqs.com/vendors/ivanti): Connect Secure 8.2, Connect Secure 8.3

_Showing 2 of 30 recorded product entries._

## How to fix CVE-2019-11510

The record marks a vendor fix as available for CVE-2019-11510. Patch reference: [https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44101/](https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44101/). Vendor advisory: [https://kb.pulsesecure.net/?atype=sa](https://kb.pulsesecure.net/?atype=sa). Because CVE-2019-11510 is KEV-listed, US federal civilian agencies were required to apply the vendor fix, or stop using the product, by 2022-05-03. Apply the vendor fix referenced above to every affected product listed in this record, then confirm the running version against the vendor advisory.

## Threat activity tracking CVE-2019-11510

1 tracked threat in the Threadlinqs corpus references CVE-2019-11510, either in the campaign’s CVE list or as an indicator on the campaign record.

- [Sen. Wyden Urges Binding Federal Mandate to Purge Internet-Facing Legacy VPNs for Zero-Trust Remote Access](https://intel.threadlinqs.com/threat/TL-2026-1774) — MEDIUM · 2026-07-27

## Sources

Enriched from CVE.org, NVD, FIRST EPSS, CISA KEV, GitHub Security Advisories, public proof-of-concept repositories, ProjectDiscovery Nuclei. Last verified by Threadlinqs on 2026-07-30. This product uses the NVD API but is not endorsed or certified by the NVD.

**Vendor advisory and patch**

- [kb.pulsesecure.net](https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44101/)
- [psirt.global.sonicwall.com](https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2019-0010)

**Third-party advisory**

- [kb.cert.org — third party advisory](https://www.kb.cert.org/vuls/id/927237)

**Vulnerability database entry**

- [securityfocus.com — vdb entry](http://www.securityfocus.com/bid/108073)

**Mailing list and disclosure**

- [lists.apache.org — mailing list](https://lists.apache.org/thread.html/ff5fa1837b6bd1b24d18a42faa75e165a4573dbe2d434910c15fd08a%40%3Cuser.guacamole.apache.org%3E)

**Other references**

- [kb.pulsesecure.net](https://kb.pulsesecure.net/?atype=sa)
- [packetstormsecurity.com](http://packetstormsecurity.com/files/154176/Pulse-Secure-SSL-VPN-8.1R15.1-8.2-8.3-9.0-Arbitrary-File-Disclosure.html)
- [badpackets.net](https://badpackets.net/over-14500-pulse-secure-vpn-endpoints-vulnerable-to-cve-2019-11510/)
- [packetstormsecurity.com (Pulse Secure SSL VPN File Disclosure NSE)](http://packetstormsecurity.com/files/154231/Pulse-Secure-SSL-VPN-File-Disclosure-NSE.html)
- [i.blackhat.com](https://i.blackhat.com/USA-19/Wednesday/us-19-Tsai-Infiltrating-Corporate-Intranet-Like-NSA.pdf)

_Showing 10 of 11 recorded references._

Canonical: https://intel.threadlinqs.com/cve/CVE-2019-11510
Full detection coverage and IOCs for threats exploiting CVE-2019-11510 via the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp
