Skip to main content
EVULNABLE Home

CVE-2019-11510

Ivanti — Ivanti Pulse Connect Secure Arbitrary File Read Vulnerability

CISA KEV · in the CISA KEV catalog since 2021-11-03

ExigentOverdue by 4.3 yearsRansomwareCISA KEVActively Exploited

What EVULNABLE says

Listed in the CISA KEV catalog, and an EPSS probability of 0.999.

Out-of-Band / Urgent Remediation

The priority band answers “how soon”, not “how bad” — see Methodology for what it weighs and where it abstains.

The evidence behind it

MeasureValueSource
CVSS base score 10.0 NVD
FIRST EPSS 0.999 (99.99th pctl) FIRST
Actively exploited Confirmed CISA KEV
Ransomware campaign use Known CISA KEV
CISA remediation deadline 2022-05-03 — Overdue by 4.3 years CISA KEV

What CISA says to do

  • Reference CISA's ED 21-03 (https://www.cisa.gov/news-events/directives/ed-21-03-mitigate-pulse-connect-secure-product-vulnerabilities) for further guidance and requirements. Note: The due date for addressing this vulnerability aligns with the requirements outlined in ED 21-03. https://nvd.nist.gov/vuln/detail/CVE-2019-11510

The primary records

This page is an opinion about urgency. Where it and a source of record disagree, the source of record is the record.

Where this sits

CVE-2019-11510 is one of the entries ranked on the priority feed and in the non-Microsoft advisories.