← Browse CVEs
CVE-2019-11510
Critical · CVSS 10EPSS 100.0%CISA KEVCWE-22 · Path Traversal
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthenticated remote attacker can send a specially crafted URI to perform an arbitrary file reading vulnerability .
References
Published
Community ground truth
Community verdict
3 verdictsNot a real issue
Includes TruePositive's curated baseline from public sources — community verdicts accrue on top.
to add your verdict.
Community real-world severity: Critical (Critical 3) — CVSS base score 10
In line with its CVSS base score.
Field notes & remediation
Verdicts are the quick signal — notes are the evidence and fixes behind them.
- 0
Confirmed exploited in the wild — listed in the CISA KEV catalog (added 2021-11-03). Linked to known ransomware campaigns. Treat as real and prioritize patching over triage.