CVE-2019-11538: Ivanti Connect Secure
High severity, CVSS 7.7. EPSS: 7.3% chance of exploitation in the next 30 days.
In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1RX before 8.1R15.1, an NFS problem could allow an authenticated attacker to access the contents of arbitrary files on the affected device.
Affected products
- Ivanti Connect Secure: version 8.1 only; version 8.2 only; version 8.3 only; version 9.0 only
Published 2019-04-26. Last modified 2026-06-17.