Evidence dossier

CVE-2019-11510

In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthenticated remote attacker can send a specially crafted URI…

Exploited in the wild (CISA KEV since Nov 3, 2021). NVD reports CVSS 3.1 10.0. EPSS estimates 100.0% exploit likelihood as of Jul 26, 2026.

87.689.2Priority evidence range
Evidence current through Aug 27, 2026, 6:09 PM UTC

As of Aug 27, 2026

Normalized restatement

In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthenticated remote attacker can send a specially crafted URI to perform an arbitrary file reading vulnerability .

State
PUBLISHED
Published
May 8, 2019
Updated
Oct 21, 2025
Evidence coverage
99%

Evidence chronology

What was known when

Download this view's receipt →
  1. Source dateSource date omittedFirst observed by CASCA
    CISA-ADP

    Record text: CISA ADP Vulnrichment

    Inspect raw assertion
    Field
    container
    Value
    CISA ADP Vulnrichment
    Original evidence ↗
  2. Source dateSource date omittedFirst observed by CASCA
    CVE Program

    Record text: CVE Program Container

    Inspect raw assertion
    Field
    container
    Value
    CVE Program Container
    Original evidence ↗
  3. Source dateSource date omittedFirst observed by CASCA
    mitre

    Record text: In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthenticated remote attacker can send a specially crafted URI to perform an arbitrary file reading vulnerability .

    Inspect raw assertion
    Field
    container
    Value
    In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthenticated remote attacker can send a specially crafted URI to perform an arbitrary file reading vulnerability .
    Original evidence ↗
  4. Source dateFirst observed by CASCA
    CISA KEV

    Exploitation cataloged: Ivanti Pulse Connect Secure Arbitrary File Read Vulnerability

    Inspect raw assertion
    Field
    observed_exploitation
    Value
    Ivanti Pulse Connect Secure Arbitrary File Read Vulnerability
    Original evidence ↗
  5. Source dateFirst observed by CASCA
    FIRST EPSS

    EPSS score: 100% probability · 100th percentile

    Inspect raw assertion
    Field
    model_probability
    Value
    Probability 0.999990000000; percentile 0.999950000000
    Original evidence ↗
ExploitationCatalog member

CISA KEV · catalog date Nov 3, 2021 · first observed Jul 19, 2026

Exploit likelihood100.00%

FIRST EPSS · score date Jul 26, 2026 · 100th percentile · first observed Jul 27, 2026

SeverityCVSS 10.0

NVD · CVSS 3.1 · first observed Jul 19, 2026 · same-version scores align in this snapshot

Evidence detail

Source limits and decisions

Why each evidence state has this value

Outside this view’s verified evidence

Reason detail begins outside this selected snapshot; the state remains source-bound.

Source comparison

Who said what

CISA-ADPIndependent enrichment
Record text

CISA ADP Vulnrichment

Inspect raw assertion
Field
container
Value
CISA ADP Vulnrichment
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
CVE ProgramDerivative copy
Record text

CVE Program Container

Inspect raw assertion
Field
container
Value
CVE Program Container
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
mitreOriginal assertion
Record text

In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthenticated remote attacker can send a specially crafted URI to perform an arbitrary file reading vulnerability .

Inspect raw assertion
Field
container
Value
In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthenticated remote attacker can send a specially crafted URI to perform an arbitrary file reading vulnerability .
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
CISA KEVOriginal assertion
Exploitation cataloged

Ivanti Pulse Connect Secure Arbitrary File Read Vulnerability

Inspect raw assertion
Field
observed_exploitation
Value
Ivanti Pulse Connect Secure Arbitrary File Read Vulnerability
Source dateFirst observed by CASCAOriginal evidence ↗
FIRST EPSSOriginal assertion
EPSS score

100% probability · 100th percentile

Inspect raw assertion
Field
model_probability
Value
Probability 0.999990000000; percentile 0.999950000000
Source dateFirst observed by CASCAOriginal evidence ↗

Applicability

Cited product scope

Trace impact →
37Underlying assertions
1Canonical products
37Target assertions
0Constraint assertions

Grouped from 1 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.

Identity source boundaries
  • Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z27d65b0f-b718-4b4f-bb79-c47c68d09dfa
  • Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z955dae73-7302-438b-aee1-058d7cc5d48e

2 scope groups

mitre · source assertedn/an/aDirect source scope
Affected: n/a
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "affected", "version": "n/a"}]
NVD CPE · APPLICATIONivanticonnect_secureVulnerable target · 37 assertions
Version 8.2; Version 8.3; Version 9.0Canonical identity product-0675def37879dcf14a27022586db7f5234f5d2c3f293e3a70a47a5da19da3b1bLinked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:ivanti:connect_secure:9.0:r2:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 31
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    59331dc5-ff5f-4bb3-905e-5a4a621f86ed
  2. cpe:2.3:a:ivanti:connect_secure:8.2:r7.1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 14
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    dcf535c6-97a2-4222-9bf4-a7d16e5598ff
  3. cpe:2.3:a:ivanti:connect_secure:8.2:r2.0:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 5
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    1d187ddb-96c8-4435-992e-cfeee24bc7c5
  4. cpe:2.3:a:ivanti:connect_secure:8.2:r7.0:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 13
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    e6d81535-5163-4dad-8aaa-61f107e11eb8
  5. cpe:2.3:a:ivanti:connect_secure:8.2:r6.0:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 12
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    784adc67-57bf-4ffa-ac13-5f2f1208f39d
  6. cpe:2.3:a:ivanti:connect_secure:8.2:r8.2:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 17
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    363c9e09-ec06-4a34-8c25-97dccaa992e1
  7. cpe:2.3:a:ivanti:connect_secure:8.2:r4.1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 9
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    a1f61a93-6e90-4063-bfca-166da0ddce38
  8. cpe:2.3:a:ivanti:connect_secure:9.0:r3.3:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 36
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    59f4a6f7-a6d4-4517-a316-7c7c002a9ed3
  9. cpe:2.3:a:ivanti:connect_secure:8.2:r8.1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 16
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    a37bef28-d0d5-46bd-a460-32734d0d63b8
  10. cpe:2.3:a:ivanti:connect_secure:8.2:r10.0:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 2
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    00f4df7b-ed7f-46fc-8b12-5527fb5a4305
  11. cpe:2.3:a:ivanti:connect_secure:8.3:r6.1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 28
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    b7fcdccf-8509-431a-b450-b18c110aae19
  12. cpe:2.3:a:ivanti:connect_secure:9.0:r3.2:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 35
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    5da976d9-a330-475e-b8c0-09ef3e08f18d
  13. cpe:2.3:a:ivanti:connect_secure:9.0:r1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 30
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    d47d09a8-4ac4-4cd9-b648-5f26453e2e1d
  14. cpe:2.3:a:ivanti:connect_secure:8.2:r1.0:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    48b04626-10a7-4a12-af3d-61c8d980aa21
  15. cpe:2.3:a:ivanti:connect_secure:8.3:r5.2:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 26
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    3837bb6e-5236-4b2d-9693-4de85c7845c3
  16. cpe:2.3:a:ivanti:connect_secure:8.3:r2:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 20
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    2a319bab-f483-4926-9700-760d8025f747
  17. cpe:2.3:a:ivanti:connect_secure:8.3:r4:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 23
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    d85a6292-ee41-487c-a1dc-0e8e443a8075
  18. cpe:2.3:a:ivanti:connect_secure:8.3:r5:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 24
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    2d829f28-4fff-40c9-af62-455ba5bb4e58
  19. cpe:2.3:a:ivanti:connect_secure:8.2:r8.0:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 15
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    2b3806f4-53e6-47b2-9d16-69b566daad97
  20. cpe:2.3:a:ivanti:connect_secure:8.2:r3.0:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 6
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    1ca6cbe1-cf6c-4d8c-bab3-0b78e56e85da
  21. cpe:2.3:a:ivanti:connect_secure:8.2:r4.0:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 8
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    3f7455ad-e662-4817-a343-9acce763b78e
  22. cpe:2.3:a:ivanti:connect_secure:8.2:r5.1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 11
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    35f94103-0db3-4d3a-8247-59e1f86743b8
  23. cpe:2.3:a:ivanti:connect_secure:8.3:r2.1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 21
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    aa6bd7fd-29a3-468c-8a85-63202eb1b625
  24. cpe:2.3:a:ivanti:connect_secure:8.2:r3.1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 7
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    761102e8-04db-465a-a592-98c5f5e0adfa
  25. cpe:2.3:a:ivanti:connect_secure:8.3:r5.1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 25
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    8dc693d8-d12b-4a0b-808a-a0808baa33dd
  26. cpe:2.3:a:ivanti:connect_secure:9.0:r2.1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 32
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    6a708c3f-9050-4475-95b3-4785d3e2cb69
  27. cpe:2.3:a:ivanti:connect_secure:8.2:r9.0:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 18
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    3ab170d9-42af-417b-8ef8-2895f54d0aee
  28. cpe:2.3:a:ivanti:connect_secure:8.2:r1.1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 1
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    183e1dd7-ee4b-47c4-99e2-cd06ed2e0d4f
  29. cpe:2.3:a:ivanti:connect_secure:8.3:r7:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 29
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    718b6320-e7be-4715-a446-541d1aada027
  30. cpe:2.3:a:ivanti:connect_secure:8.3:r3:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 22
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    00aa23df-ca30-41fc-9563-c95ba7d31129
  31. cpe:2.3:a:ivanti:connect_secure:9.0:r3:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 33
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    52851aaa-88fb-40bc-b41a-b821f6ba9f79
  32. cpe:2.3:a:ivanti:connect_secure:8.3:r6:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 27
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    72430b2f-a311-4df7-abbb-1ee0baf507fd
  33. cpe:2.3:a:ivanti:connect_secure:8.2:r11.0:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 3
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    4a5af6a0-6613-4b15-a1a3-aeac0ef7e374
  34. cpe:2.3:a:ivanti:connect_secure:8.2:r5.0:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 10
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    b5bf94c4-0456-4cb1-9cc5-02a316c84e09
  35. cpe:2.3:a:ivanti:connect_secure:8.3:r1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 19
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    2871aad9-fc12-4e2d-b722-0f721d7fe101
  36. cpe:2.3:a:ivanti:connect_secure:8.2:r12.0:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 4
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    970c2bee-5798-4a5f-8d4e-7970bfcf0cd2
  37. cpe:2.3:a:ivanti:connect_secure:9.0:r3.1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 34
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    f05dc11e-7c41-450b-a2bf-603e9252bb40

Affected-product evidence

Accepted scope and product mapping

0 canonical links · 0 source-reported links

Applicability remains source-scoped; safety and exposure remain unassessed.

Assessments

CVSS by origin

10.0
NVDCVSS 3.1 · role Primary · priority eligiblevalid_matchCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
7.5
NVDCVSS 2.0 · role Primary · priority eligiblevalid_matchAV:N/AC:L/Au:N/C:P/I:P/A:P
9.9
cve@mitre.orgCVSS 3.0 · role Secondary · priority eligiblevalid_matchCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
9.9
mitreCVSS 3.0 · role unknown · display onlyDirect record assessment retained outside normalized eligibilityCVSS:3.0/AC:L/AV:N/A:H/C:H/I:H/PR:L/S:C/UI:N

Evidence boundaries

  • KEV membership is authoritative for the catalog, not proof of exposure in any environment.
  • EPSS is a dated model probability and not an individual-environment prediction.
  • Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
  • NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
  • Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
  • NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
  • Affected-product evidence remains source-scoped; canonical linkage is required before applicability scoring.
  • Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
  • OSV aggregation and OSV-converted NVD material are not independent corroboration.
  • Red Hat facts are vendor assertions for the exact supplied products.
  • Nonmembership and not-yet-observed states are not proof of safety.