HIGH

CVE-2019-11542

CVSS v3

7.2

HIGH

EPSS Score

48.4%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1RX before 8.1R15.1 and Pulse Policy Secure version 9.0RX before 9.0R3.2, 5.4RX before 5.4R7.1, 5.3RX before 5.3R12.1, 5.2RX before 5.2R12.1, and 5.1RX before 5.1R15.1, an authenticated attacker (via the admin web interface) can send a specially crafted message resulting in a stack buffer overflow.

Technical details

Published
4/26/2019

Frequently asked questions

What is CVE-2019-11542?

In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1RX before 8.1R15.1 and Pulse Policy Secure version 9.0RX before 9.0R3.2, 5.4RX before 5.4R7.1, 5.3RX before 5.3R12.1, 5.2RX before 5.2R12.1, and 5.1RX before 5.1R15.1, an authenticated attacker (via the admin web interface) can send a specially crafted message resulting in a stack buffer overflow.

Is CVE-2019-11542 actively exploited?

Active exploitation of CVE-2019-11542 has not been confirmed. The EPSS score is 48.4%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2019-11542?

CVE-2019-11542 has a CVSS v3 base score of 7.2 (HIGH severity).

Is CVE-2019-11542 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.