.. / CVE-2019-11510

Exploit for Pulse Connect Secure SSL VPN Arbitrary File Read (CVE-2019-11510)

Description:

Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4 all contain an arbitrary file reading vulnerability that could allow unauthenticated remote attackers to send a specially crafted URI to gain improper access.

Nuclei Template

View the template here CVE-2019-11510.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2019/CVE-2019-11510.yaml
Copy

References:

https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44101/
https://blog.orange.tw/2019/09/attacking-ssl-vpn-part-3-golden-pulse-secure-rce-chain.html
http://packetstormsecurity.com/files/154176/Pulse-Secure-SSL-VPN-8.1R15.1-8.2-8.3-9.0-Arbitrary-File-Disclosure.html
http://packetstormsecurity.com/files/154231/Pulse-Secure-SSL-VPN-File-Disclosure-NSE.html
https://nvd.nist.gov/vuln/detail/CVE-2019-11510