S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2019-11510 Scanner

CVE-2019-11510 scanner - Arbitrary File Read vulnerability in Pulse Secure Pulse Connect Secure (PCS)

Est. Time~30 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.1k
Times Used
continuous scan runs
3.7k
Continuously Checked
assets under CS
12
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2019-11510
10.0
CVSScritical
Exploitable remotely over the internet · low-privilege account sufficient.

In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthenticated remote attacker can send a specially crafted URI to perform an arbitrary file reading vulnerability .

Attack Vector
Network
Privileges Req.
Low
User Interaction
None
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

Pulse Secure Pulse Connect Secure (PCS) is a virtual private network (VPN) solution that is used to provide secure remote access to corporate networks and resources. It allows employees to work remotely from anywhere and anytime while maintaining the security of the network. Pulse Secure PCS has become a popular choice for businesses as a secure remote access solution due to its ease of installation and configuration.

CVE-2019-11510 is a vulnerability that has been detected in the Pulse Secure Pulse Connect Secure (PCS) product. This vulnerability allows an unauthenticated remote attacker to send a specially crafted URI to perform an arbitrary file reading vulnerability. This vulnerability affects multiple versions of the product, including 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4.

When exploited, the CVE-2019-11510 vulnerability could lead to the compromise of confidential corporate data and resources. The attacker could use this vulnerability to access sensitive information, such as user credentials, intellectual property, and financial data. This could result in financial losses, reputational damage, and legal implications for the affected company.

Thanks to the pro features of the s4e.io platform, readers of this article can easily and quickly learn about vulnerabilities in their digital assets. The platform offers comprehensive vulnerability scanning and assessment services that help businesses identify and address security vulnerabilities before they can be exploited. These services include automated vulnerability scanning, manual penetration testing, and security consultation from expert security professionals. By leveraging the s4e.io platform, businesses can ensure the security of their digital assets and protect themselves against potential cyber threats.

 

REFERENCES

Solution Advice

There are several precautions that can be taken to protect against this vulnerability. These include:

  • Apply the latest security patches and updates from Pulse Secure.
  • Implement network segmentation to restrict access to critical systems and resources.
  • Configure strong authentication and access controls for remote access to corporate networks.
  • Monitor network traffic and user activity for suspicious activity.
  • Implement web application firewalls and intrusion detection systems to detect and prevent attacks.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.