>> All posts

CVE-2019-11510: Pulse/Ivanti Connect Secure arbitrary file read, unauthenticated and mass-exploited

The short version: CVE-2019-11510 is a pre-authentication path-traversal flaw in Pulse Connect Secure (now Ivanti Connect Secure). By sending a crafted URI, an unauthenticated attacker reads arbitrary files off the appliance — including plaintext credentials, private keys, and session data they can replay. It was exploited at scale for years and used as a ransomware entry point. It's an old bug, but exposed, unpatched appliances still exist. If you have one, treat it as compromised until proven otherwise. Steady hands — but move.

At a glance

FactDetail
Our severity takeHigh — unauthenticated credential and secrets disclosure on a VPN appliance
CVSS v3.1 (NVD)10.0 — Critical · AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CVSS (CNA, v3.0)9.9 — Critical · AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
EPSS~99.99% · 99.99th percentile (2026-07-17)
In CISA KEV?Yes — remediation was due 2022-05-03
Known exploited?Yes — mass-exploited; KEV notes known ransomware-campaign use
Vulnerability typePath traversal → arbitrary file read → credential, key, and session disclosure
Requires authenticated session?No — pre-authentication
AffectedPulse Connect Secure 8.2 < 8.2R12.1, 8.3 < 8.3R7.1, 9.0 < 9.0R3.4
Fixed in8.2R12.1 · 8.3R7.1 · 9.0R3.4 (and later)

What you need to know

CVE-2019-11510 lets an unauthenticated attacker walk outside the intended web path and read arbitrary files on the appliance. On a VPN gateway, those files include the things that matter most: cached plaintext credentials, private keys, and active session tokens.

That's why the practical impact runs past "information disclosure":

  • It hands over credentials and sessions. An attacker doesn't need to exploit anything else — they read the secrets and log in as a legitimate user, or replay a live session.
  • It's a perimeter access appliance. Compromise reaches inward, into the network the VPN was protecting.
  • It was mass-exploited. For years it was one of the most abused vulnerabilities on the internet, including as an initial-access vector for ransomware operators — so an exposed, unpatched appliance should be assumed touched.

How serious we see it

High — and NVD's 10.0 is not hyperbole here.

An unauthenticated read of every secret on an internet-facing VPN behaves like a full authentication bypass, because it literally hands over the credentials and sessions that authentication depends on. The bounded, reassuring part is that it's narrow and long-fixed: it affects specific older builds, patches have existed for years, and exposure is trivial to determine. The catch is history — because this bug was abused so heavily for so long, any appliance that sat exposed and unpatched should be treated as compromised, not merely patched.

Recommendations

Straight from Pulse Secure's / Ivanti's advisory and CISA:

  1. Patch immediately (or replace). Upgrade to 8.2R12.1 / 8.3R7.1 / 9.0R3.4 or later; these builds are old, so migrating to a current, supported release is the better move.
  2. Assume the secrets leaked — rotate everything. Reset all appliance and account credentials, private keys, and certificates, and terminate active sessions.
  3. Hunt for prior compromise. Review authentication and session logs for anomalous or impossible-travel logins and reused tokens.
  4. Harden exposure. Restrict who can reach the gateway; keep the management interface off the public internet.
  5. Confirm your exposure first. Verify whether any internet-facing Pulse/Ivanti Connect Secure appliance is on an affected build.

How BreachRisk sees it

BreachRisk works from the outside in, the way an attacker does. From little more than your domain it discovers internet-facing Pulse/Ivanti Connect Secure interfaces, fingerprints the build, and flags exposure tied to KEV-listed, actively exploited vulnerabilities like this one — pushed to the top of your results because it's in KEV.

Old vulnerabilities are exactly where a continuous, attacker's-eye view earns its keep: the appliance everyone forgot is still on the internet, and it's the one attackers still scan for. BreachRisk keeps it on your radar instead of theirs.

References

See your cyber risk, proven.