Skip to main content

CVE detail

CVE-2019-11510

In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthenticated remote attacker can send a specially crafted URI to perform an arbitrary file reading vulnerability .

CVSS 10.0 · CriticalBuzz score 74.0KEV listed

Buzz score

Why this CVE is surfacing

Buzz score total 74.0

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 30.0 · diversity 19.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Mention score
30.0
88 evidence mentions in the snapshot
Diversity score
19.0
8 sources across 2 categories
KEV score
25.0
Known exploited vulnerability present
OTX score
0.0
0 OTX pulses
PoC score
0.0
0 repos · best confidence N/A
Best PoC traction
0
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
0
within the 30d window
Peak daily
0
highest bucket

Evidence

Source links by recency

Newest mentions first
88 source links · newest first
  • The Convergence of Cloud Secrets & AI RiskSentinelOne Labs

    initial access points. The top verified exploit paths continue to involve older, critical CVEs, including: Shellshock ( CVE-2014-6271 ) FortiGate SSL VPN credential disclosure ( CVE-2018-13379 ) Pulse Secure VPN arbitrary file read ( CVE-2019-11510 ) Webmin RCE ( CVE-2019-15107 ) Barracuda ESG zero-day backdoor ( CVE-2023-1698 ) Since these vulnerabil

    vendorwww.sentinelone.comMay 13, 2026, 6:11 PM
  • Old vulnerabilities are still a big problemHelp Net Security

    A recently flagged phishing campaign aimed at delivering the Agent Tesla RAT to unsuspecting users takes advantage of old vulnerabilities in Microsoft Office that allow remote code execution. “Despite fixes for CVE-2017-11882/CVE-2018-0802 being released by Microsoft in November, 2017 and January, 2018, this vulnerability remains popular amongst threat actors, suggesting there are still unpatched devices in the wild, even after over five years,” says Fortinet researcher Xiaopeng Zhang. “We are observing and mitigating 3000 attacks … More →

    newswww.helpnetsecurity.comSep 6, 2023, 1:51 PM
  • Top 12 vulnerabilities routinely exploited in 2022Help Net Security

    Cybersecurity agencies from member countries of the Five Eyes intelligence alliance have released a list of the top 12 vulnerabilities routinely exploited in 2022, plus 30 additional ones also “popular” with attackers. The top 12 “In 2022, malicious cyber actors exploited older software vulnerabilities more frequently than recently disclosed vulnerabilities and targeted unpatched, internet-facing systems. Proof of concept (PoC) code was publicly available for many of the software vulnerabilities or vulnerability chains likely facilitating exploitation … More →

    newswww.helpnetsecurity.comAug 4, 2023, 1:17 PM
  • More than 4,000 internet-accessible Pulse Connect Secure hosts are impacted by at least one known vulnerability, attack surface management firm Censys warns.

    newswww.securityweek.comDec 9, 2022, 10:36 AM
  • Several US government agencies have issued a joint cybersecurity advisory to provide information on the techniques and tactics that China-linked threat actors have been using to compromise telecom companies and network services providers.

    newswww.securityweek.comJun 9, 2022, 1:00 PM
  • China-linked threat actors have breached telecommunications companies and network service providers to spy on the traffic and steal data. US NSA, CISA, and the FBI published a joint cybersecurity advisory to warn that China-linked threat actors have breached telecommunications companies and network service providers. The nation-state actors exploit publicly known vulnerabilities to compromise the target […]

    newssecurityaffairs.comJun 8, 2022, 9:53 AM
  • Syxsense has announced a new security and endpoint management solution that delivers vulnerability monitoring and remediation across devices and network environments. The IT management and endpoint security vendor stated that the platform – Syxsense Enterprise – delivers a unified solution that scans and manages all endpoints, resolves problems in real-time, and reduces the risks associated […]

    newswww.csoonline.comMay 3, 2022, 4:01 AM
  • Cybersecurity and Infrastructure Security Agency (CISA) published a list of 2021’s top 15 most exploited software vulnerabilities Cybersecurity and Infrastructure Security Agency (CISA) published the list of 2021’s top 15 most exploited software vulnerabilities This joint Cybersecurity Advisory (CSA) was coauthored by cybersecurity agencies of the United States, Australia, Canada, New Zealand, and the United […]

    newssecurityaffairs.comApr 28, 2022, 1:49 PM
  • Global cybersecurity authorities have published a joint advisory on the 15 Common Vulnerabilities and Exposures (CVEs) most routinely exploited by malicious cyber actors in 2021. The advisory is co-authored by the U.S. Cybersecurity and Infrastructure Security Agency (CISA), U.S. National Security Agency (NSA), U.S. Federal Bureau of Investigation (FBI), Australian Cyber Security Centre (ACSC), Canadian […]

    newswww.csoonline.comApr 28, 2022, 10:55 AM
  • The 15 most exploited vulnerabilities in 2021Help Net Security

    In 2021, threat actors aggressively exploited newly disclosed critical software vulnerabilities to hit a broad set of targets worldwide, says the latest advisory published by the US Cybersecurity and Infrastructure Security Agency. Most exploited vulnerabilities, new and old Compiled by cybersecurity authorities from the Five Eyes intelligence alliance, the list of top 15 CVEs routinely exploited by attackers in 2021 looks like this: CVE-2021-44228 (aka Log4Shell) – in Apache Log4j CVE-2021-40539 – in Zoho ManageEngine … More →

    newswww.helpnetsecurity.comApr 28, 2022, 7:48 AM
  • We provide an overview of known cyberthreats related to Russia-Ukraine cyber activity, including DDoS attacks, HermeticWiper and defacement, and share recommendations for proactive defense.

    vendorunit42.paloaltonetworks.comFeb 22, 2022, 11:00 PM
  • US authorities warn critical infrastructure operators of the threat of cyberattacks orchestrated by Russia-linked threat actors. US Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), and the National Security Agency (NSA) issued a joint alert to warn critical infrastructure operators about threats from Russian state-sponsored hackers. “This joint Cybersecurity Advisory (CSA)—authored […]

    newssecurityaffairs.comJan 12, 2022, 8:01 PM
  • Security researchers have recently seen a notorious cyberespionage group with ties to the Russian government deploy a new backdoor that’s designed to hook into Active Directory Federation Services (AD FS) and steal configuration databases and security token certificates. In a new report, Microsoft attributes the malware program called FoggyWeb to a group the company tracks […]

    newswww.csoonline.comSep 30, 2021, 7:12 PM
  • Microsoft Office 365 email accounts of employees at 27 US Attorneys’ offices were breached by the Russia-linked SVR group as part of the SolarWinds hack, DoJ warns. The US Department of Justice revealed that the Microsoft Office 365 email accounts of employees at 27 US Attorneys’ offices were hacked by the Russia-linked SVR (aka APT29, Cozy Bear, and The Dukes) during the SolarWinds attack. The […]

    newssecurityaffairs.comJul 31, 2021, 6:00 PM
  • 26th July – Threat Intelligence ReportCheck Point Research

    For the latest discoveries in cyber research for the week of 26th July, please download our Threat Intelligence Bulletin. Top Attacks and Breaches US officials have reported that Chinese state-sponsored threat actors successfully breached 13 US oil and natural gas pipeline companies between 2011 and 2013. The hackers gained initial access using a spear-phishing campaign, […]

    vendorresearch.checkpoint.comJul 26, 2021, 1:54 PM
  • U.S. CISA released an alert today about several stealth malware samples that were found on compromised Pulse Secure devices. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) published a security alert related to the discovery of 13 malware samples on compromised Pulse Secure devices, many of which were undetected by antivirus products. Experts pointed out […]

    newssecurityaffairs.comJul 22, 2021, 12:39 PM
  • Remember when we told you to patch your VPNs already? I hate to say “I told you so”, but I informed…

    newswww.malwarebytes.comJun 20, 2021, 5:00 PM
  • The UK and US cybersecurity agencies have published a report detailing techniques used by Russia-linked cyberespionage group known APT29 (aka Cozy Bear). Today, UK NCSC and CISA-FBI-NSA cybersecurity agencies published a joint security advisory that warns organizations to patch systems immediately to mitigate the risk of attacks conducted by Russia-linked SVR group (aka APT29, Cozy Bear, and The Dukes)). The […]

    newssecurityaffairs.comMay 7, 2021, 9:03 PM
  • Embattled VPN technology vendor Pulse Secure on Monday updated an “out-of-cycle” advisory with patches for four major security vulnerabilities, including belated cover for an issue that’s already been exploited by advanced threat actors.

    newswww.securityweek.comMay 3, 2021, 4:26 PM
  • Attackers have been exploiting several old and one zero-day vulnerability (CVE-2021-22893) affecting Pulse Connect Secure (PCS) VPN devices to breach a variety of defense, government, and financial organizations around the world, Mandiant/FireEye has warned on Tuesday. Phil Richards, the Chief Security Officer at Ivanti – the company that acquired Pulse Secure in late 2020 – said that the zero-day vulnerability “impacted a very limited number of customers,” and that the software updates plugging the flaw … More →

    newswww.helpnetsecurity.comApr 21, 2021, 9:45 AM
  • Multiple threat actors are actively engaged in the targeting of four vulnerabilities in Pulse Secure VPN appliances, including a zero-day identified this month that won’t be patched until next month.

    newswww.securityweek.comApr 20, 2021, 9:23 PM
  • Pulse Secure has alerted customers to the existence of an exploitable chain of attack against its Pulse Connect Secure (PCS) appliances….

    newswww.malwarebytes.comApr 20, 2021, 5:00 PM
  • 19th April – Threat Intelligence ReportCheck Point Research

    For the latest discoveries in cyber research for the week of 19th April, please download our Threat Intelligence Bulletin. Top Attacks and Breaches The U.S National Security Agency (NSA), the Cybersecurity and infrastructure security agency (CISA), and the Federal Bureau of Investigation (FBI) have published a joint advisory warning that a Russia-linked APT group, APT25, […]

    vendorresearch.checkpoint.comApr 19, 2021, 5:54 PM
  • The US government warned that Russian cyber espionage group SVR is exploiting five known vulnerabilities in enterprise infrastructure products. The U.S. National Security Agency (NSA), the Cybersecurity and Infrastructure Security Agency (CISA), and the Federal Bureau of Investigation (FBI) have published a joint advisory that warns that Russia-linked APT group SVR (aka APT29, Cozy Bear, and The Dukes). […]

    newssecurityaffairs.comApr 16, 2021, 12:26 PM
  • The U.S. government on Thursday warned that Russian APT operators are exploiting five known — and already patched — vulnerabilities in corporate VPN infrastructure products, insisting it is “critically important” to mitigate these issues immediately.

    newswww.securityweek.comApr 15, 2021, 2:15 PM
  • 5th April – Threat Intelligence ReportCheck Point Research

    For the latest discoveries in cyber research for the week of 5th April, please download our Threat Intelligence Bulletin. Top Attacks and Breaches Personal information of some 553 million Facebook users from 100 countries has been stolen and published online for free in a hacking forum. The records include full name, Facebook ID, phone number, […]

    vendorresearch.checkpoint.comApr 5, 2021, 4:14 PM
  • In a recent report, Trend Micro announced it detected 119,000 cyber threats per minute in 2020 as home workers and infrastructure came under new pressure from attacks. Attacks on homes surged The report also shows that home networks were a major draw last year for cybercriminals looking to pivot to corporate systems, or compromise and conscript IoT devices into botnets. Attacks on homes surged 210% to reach nearly 2.9 billion—amounting to 15.5% of all homes. … More →

    newswww.helpnetsecurity.comMar 1, 2021, 5:00 AM
  • During the COVID-19 pandemic, companies stayed operational while keeping staff safe by enabling their employees to work from home. While this kept businesses running, it introduced another risk: security problems at the network perimeter. Our Security Navigator 2021 report notes that the rush to remote working, combined with a marked rise in discovered vulnerabilities, has […]

    newswww.csoonline.comFeb 12, 2021, 10:40 AM
  • Attacks conducted by Iranian hackers against Israeli companies involved the deployment of ransomware and theft of information, threat intelligence company ClearSky reported last week.

    newswww.securityweek.comDec 21, 2020, 4:52 AM
  • Palo Alto Networks commends FireEye for transparency around its reported breach and is working to use the information shared to protect our customers.

    vendorunit42.paloaltonetworks.comDec 11, 2020, 5:10 AM
  • The three stages of security risk reprioritizationHelp Net Security

    What began as a two-week remote working environment, due to COVID-19 has now stretched past the nine-month mark for many. The impact of telework on organizations can be felt across departments, including IT and security, which drove the almost overnight digital transformation that swept across the globe. While organizations across various sectors were faced with the challenge of maximizing their telework posture, those in government services had the extra burden of supporting employees who needed … More →

    newswww.helpnetsecurity.comDec 2, 2020, 6:00 AM
  • A threat actor has published online a list of one-line exploits to steal VPN credentials from over 49,000 vulnerable Fortinet VPNs. A threat actor, who goes online with the moniker “pumpedkicks,” has leaked online a list of exploits that could be exploited to steal VPN credentials from almost 50,000 Fortinet VPN devices. Researchers from Bank Security first […]

    newssecurityaffairs.comNov 22, 2020, 6:07 PM
  • China-linked threat actor APT10 was observed launching a large-scale campaign against Japanese organizations and their subsidiaries.

    newswww.securityweek.comNov 19, 2020, 7:28 PM
  • 26th October – Threat Intelligence BulletinCheck Point Research

    For the latest discoveries in cyber research for the week of 26th October 2020, please download our Threat Intelligence Bulletin. Top Attacks and Breaches Voter database in Hall Country, Georgia, used to verify voter signatures, has been breached by ransomware, alongside other government systems. This might be the first official election resource to be hit […]

    vendorresearch.checkpoint.comOct 26, 2020, 1:47 PM
  • The U.S. National Security Agency this week released an advisory containing information on 25 vulnerabilities that are being actively exploited or targeted by Chinese state-sponsored threat actors.

    newswww.securityweek.comOct 21, 2020, 11:06 AM
  • The US Cybersecurity and Infrastructure Security Agency (CISA) has released a list of 25 vulnerabilities Chinese state-sponsored hackers have been recently scanning for or have exploited in attacks. “Most of the vulnerabilities […] can be exploited to gain initial access to victim networks using products that are directly accessible from the Internet and act as gateways to internal networks. The majority of the products are either for remote access or for external web services, and … More →

    newswww.helpnetsecurity.comOct 21, 2020, 10:23 AM
  • The US National Security Agency (NSA) has shared the list of top 25 vulnerabilities exploited by Chinese state-sponsored hacking groups in attacks in the wild. The US National Security Agency (NSA) has published a report that includes details of the top 25 vulnerabilities that are currently being exploited by China-linked APT groups in attacks in the […]

    newssecurityaffairs.comOct 20, 2020, 7:28 PM
  • U.S. Bookstore giant Barnes & Noble has disclosed a cyber attack and that the threat actors have exposed the customers’ data. Barnes & Noble, Inc., is an American bookseller with the largest number of retail outlets in the United States in fifty states. The bookseller also operated the Nook Digital, which is a spin-off division that […]

    newssecurityaffairs.comOct 15, 2020, 1:18 PM
  • US government networks are under attack, threat actors chained VPN and Windows Zerologon flaws to gain unauthorized access to elections support systems. The Federal Bureau of Investigation (FBI) and the Cybersecurity and Infrastructure Security Agency (CISA) published a joint security alert to warn of attackers combining VPN and Windows Zerologon flaws to target government networks. […]

    newssecurityaffairs.comOct 12, 2020, 11:29 AM
  • A threat actor was able to compromise the network of a federal agency and create a reverse proxy and install malware, the Cybersecurity and Infrastructure Security Agency (CISA) reported on Thursday.

    newswww.securityweek.comSep 25, 2020, 11:07 AM
  • Cybersecurity and Infrastructure Security Agency (CISA) revealed that a hacker breached a US federal agency and exfiltrated data. Cybersecurity and Infrastructure Security Agency (CISA) revealed that a hacker breached a US federal agency and threat actors exfiltrated data. CISA published a detailed incident report related to the incident but didn’t disclose the name of the […]

    newssecurityaffairs.comSep 25, 2020, 9:40 AM
  • US Department of Justice announced indictments against 5 Chinese nationals alleged members of a state-sponsored hacking group known as APT41. The United States Department of Justice this week announced indictments against five Chinese nationals believed to be members of the cyber-espionage group known as APT41 (Winnti, Barium, Wicked Panda and Wicked Spider). US authorities are […]

    newssecurityaffairs.comSep 17, 2020, 9:59 AM
  • The United States Department of Justice on Wednesday announced indictments against five Chinese nationals believed to be part of a state-sponsored hacking group known as APT41. Also known as Winnti , Barium, Wicked Panda and Wicked Spider, the hackers allegedly launched cyberattacks on more than 100 companies in the United States and abroad. Their targets, the DoJ says, include software and video game companies, computer hardware makers, telecom providers, and social media organizations, but also governments, non-profit entities, universities , and think tanks, not to mention pro-democracy politicians and activists in Hong Kong. In August 2019 and August 2020, a federal grand jury returned two separate indictments charging the five Chinese nationals with facilitating “theft of source code, software code signing certificates, customer account data, and valuable business information,” the DoJ revealed. The hackers also engaged in ransomware and crypto-jacking attacks. The five residents…

    newswww.securityweek.comSep 16, 2020, 6:38 PM
  • Threat actors affiliated with the Chinese Ministry of State Security (MSS) continue to target U.S. government agencies, the Cybersecurity and Infrastructure Security Agency (CISA) says in a new alert.

    newswww.securityweek.comSep 15, 2020, 2:21 PM
  • CISA published an advisory on China-linked groups targeting government agencies by exploiting flaws in Microsoft Exchange, Citrix, Pulse, and F5 systems. CISA published a security advisory warning of a wave of attacks carried out by China-linked APT groups affiliated with China’s Ministry of State Security. Chinese state-sponsored hackers have probed US government networks looking for vulnerable networking […]

    newssecurityaffairs.comSep 15, 2020, 9:16 AM
  • US-based supplier of video delivery software solutions, SeaChange International, revealed that a ransomware attack disrupted its operations in Q1 2020. SeaChange International, a US-based supplier of video delivery software solutions, revealed that a ransomware attack has disrupted its operations during the first quarter of 2020. SeaChange’s customers include major organizations such as BBC, Cox, Verizon, […]

    newssecurityaffairs.comSep 10, 2020, 7:55 AM
  • The biggest security trend for 2020 has been the increase of COVID-19-related phishing and other attacks targeting remote workers. New York City, for example, has gone from having to protect 80,000 endpoints to around 750,000 endpoints in its threat management since work-from-home edicts took place. As noted in a recent Check Point Software Technologies mid-year […]

    newswww.csoonline.comSep 9, 2020, 10:00 AM
  • A hacking group believed to be linked to the Iranian government was observed targeting a critical vulnerability that F5 Networks addressed in its BIG-IP application delivery controller (ADC) in early July.

    newswww.securityweek.comSep 1, 2020, 10:43 AM
  • Iran-linked APT group Pioneer Kitten is now trying to monetize its efforts by selling access to some of the networks it has hacked to other hackers. Iran-linked APT group Pioneer Kitten, also known as Fox Kitten or Parisite, is now trying to monetize its efforts by selling access to some of the networks it has […]

    newssecurityaffairs.comSep 1, 2020, 9:22 AM
  • The typical timing of patch releases, exploits and CVE publication underscores the need for timely patching and effective vulnerability management.

    vendorunit42.paloaltonetworks.comAug 26, 2020, 1:00 PM
  • ZDNet reported in exclusive that a list of passwords for 900+ enterprise VPN servers has been shared on a Russian-speaking hacker forum. ZDNet has reported in exclusive that a list of plaintext usernames and passwords for 900 Pulse Secure VPN enterprise servers, along with IP addresses, has been shared on a Russian-speaking hacker forum. ZDNet […]

    newssecurityaffairs.comAug 5, 2020, 1:26 PM
  • NetWalker ransomware operators continue to be very active, according to McAfee the cybercrime gang has earned more than $25 million since March 2020. McAfee researchers believe that the NetWalker ransomware operators continue to be very active, the gang is believed to have earned more than $25 million since March 2020. The malware has been active […]

    newssecurityaffairs.comAug 4, 2020, 8:47 AM
  • The FBI has issued a security alert about Netwalker ransomware attacks targeting U.S. and foreign government organizations. The FBI has issued a new security flash alert to warn of Netwalker ransomware attacks targeting U.S. and foreign government organizations. The feds are recommending victims, not to pay the ransom and reporting incidents to their local FBI field offices. The flash […]

    newssecurityaffairs.comAug 2, 2020, 4:29 PM
  • The Federal Bureau of Investigation this week released an alert to warn businesses of ongoing cyberattacks involving the NetWalker ransomware.

    newswww.securityweek.comJul 30, 2020, 12:43 PM
  • In a recently released report by the UK National Cyber Security Centre (NCSC), whose findings have been backed by Canada’s Communications Security Establishment (CSE) and the US NSA and CISA (Cybersecurity and Infrastructure Security Agency), the agency has warned about active cyber attacks targeting biomedical organizations that are involved in the development of a COVID-19 vaccine. On Friday, BitSight researchers shared the results of a study that looked for detectable security issues at a number … More →

    newswww.helpnetsecurity.comJul 17, 2020, 12:22 PM
  • Researchers at Poland-based cybersecurity firm REDTEAM.PL have observed Black Kingdom ransomware attacks that exploit a Pulse Secure VPN vulnerability patched last year.

    newswww.securityweek.comJun 16, 2020, 2:11 PM
  • Black Kingdom ransomware operators are targeting organizations using unpatched Pulse Secure VPN software to deploy their malware. Researchers from security firm REDTEAM reported that operators behind the Black Kingdom ransomware are targeting enterprises exploiting the CVE-2019-11510 flaw in Pulse Secure VPN software to gain access to the network. Black Kingdom ransomware was first spotted in […]

    newssecurityaffairs.comJun 15, 2020, 1:39 PM
  • Elexon, a middleman in the UK power grid network, recently reported it was hit by a cyber attack. Elexon, a middleman in the UK power grid network, was the victim of a cyber attack, the incident impacted only affected the internal IT network, including the company’s email server, and employee laptops “Hackers have targeted a critical […]

    newssecurityaffairs.comMay 17, 2020, 7:57 AM
  • Several Microsoft Office vulnerabilities that were patched years ago continue to be among the security flaws most exploited in attacks, the U.S. government warns.

    newswww.securityweek.comMay 13, 2020, 4:43 PM
  • The US Cybersecurity and Infrastructure Security Agency (CISA) is urging organizations to patch a slew of old and new software vulnerabilities that are routinely exploited by foreign cyber actors and cyber criminals. “Foreign cyber actors continue to exploit publicly known—and often dated—software vulnerabilities against broad target sets, including public and private sector organizations. Exploitation of these vulnerabilities often requires fewer resources as compared with zero-day exploits for which no patches are available,” the agency noted. … More →

    newswww.helpnetsecurity.comMay 13, 2020, 9:49 AM
  • We've detected an uptick in Maze ransomware samples across multiple industries and created a general threat assessment post on the group behind it.

    vendorunit42.paloaltonetworks.comMay 8, 2020, 1:00 PM
  • How to thwart human-operated ransomware campaigns?Help Net Security

    Most ransomware campaigns hitting healthcare organizations and critical services right now are just the final act of a months-long compromise. “Using an attack pattern typical of human-operated ransomware campaigns, attackers have compromised target networks for several months beginning earlier this year and have been waiting to monetize their attacks by deploying ransomware when they would see the most financial gain,” says the Microsoft Threat Protection Intelligence Team. Organizations who have yet to witness the final … More →

    newswww.helpnetsecurity.comApr 30, 2020, 11:42 AM
  • 27th April – Threat Intelligence BulletinCheck Point Research

    For the latest discoveries in cyber research for the week of 27th April 2020, please download our Threat Intelligence Bulletin. Top Attacks and Breaches Check Point has investigated a Business Email Compromise attack targeting a financial organization and their business partner. The attacking group, the Florentine Banker, manipulated four transactions of over 1 million GBP […]

    vendorresearch.checkpoint.comApr 27, 2020, 11:18 AM
  • The popular SeaChange video platform is the latest victim of the Sodinokibi Ransomware gang, which is threatening to leak the stolen data. SeaChange International, the multinational supplier of video delivery software solutions, was the victim of the Sodinokibi Ransomware gang. The crew has published images of the data they claim to have stolen before encrypting the […]

    newssecurityaffairs.comApr 24, 2020, 12:17 PM
  • Patching vulnerable enterprise VPNs from Pulse Secure is not enough to keep out malicious actors who have already exploited a vulnerability, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) warns.

    newswww.securityweek.comApr 20, 2020, 1:43 PM
  • As COVID-19 slowly spread across the globe, consumer demand for commercial virtual private network (VPN) services has soared – both for security reasons and for bypassing geo-blocking of (streaming) content. Not unexpectedly, enterprise VPN use has also greatly increased, and so has the use of the Remote Desktop Protocol (RDP), a popular and common means for remotely managing a computer over a network connection. Increased enterprise RDP and VPN use Shodan creator John Matherly has … More →

    newswww.helpnetsecurity.comMar 30, 2020, 11:13 AM
  • The financial technology firm Finastra announced it has suffered a ransomware attack that took down its some of its systems. Finastra, the UK leading financial technology provider, announced that some of its servers were shut down in response to a ransomware attack that the company detected. Finastra provides financial software and services to more than 9,000 customers […]

    newssecurityaffairs.comMar 21, 2020, 7:20 PM
  • Infamous Iranian hacking groups APT33 and APT34 appear to have been working together for the past three years to compromise dozens of organizations worldwide, and their attacks involved some of the enterprise VPN vulnerabilities disclosed last year, ClearSky reports.

    newswww.securityweek.comFeb 17, 2020, 2:53 PM
  • 17th February – Threat Intelligence BulletinCheck Point Research

    For the latest discoveries in cyber research for the week of 17th February 2020, please download our Threat Intelligence Bulletin. Top Attacks and Breaches Terrorist organization Hamas has targeted Israeli soldiers using a catfishing attack. Check Point researchers have detailed how the attack took place, in a manner similar to ones used in the past […]

    vendorresearch.checkpoint.comFeb 17, 2020, 1:59 PM
  • Iranian hackers have been hacking VPN servers to plant backdoors in companies around the world Iran-linked attackers targeted Pulse Secure, Fortinet, Palo Alto Networks, and Citrix VPNs to hack into large companies as part of the Fox Kitten Campaign. During the last quarter of 2019, experts from security firm ClearSky uncovered a hacking campaign tracked […]

    newssecurityaffairs.comFeb 17, 2020, 6:07 AM
  • 13th January – Threat Intelligence BulletinCheck Point Research

    For the latest discoveries in cyber research for the week of 13th January 2020, please download our Threat Intelligence Bulletin. Top Attacks and Breaches Austria’s foreign ministry has suffered a serious cyber-attack, allegedly conducted by a foreign state. US government-funded low-cost UMX mobile phones include preinstalled “unremovable” malware. The malware, a variant of HiddenAds, is […]

    vendorresearch.checkpoint.comJan 13, 2020, 12:45 PM
  • The US DHS CISA agency is warning organizations that threat actors continue to exploit the CVE-2019-11510 Pulse Secure VPN vulnerability. The U.S. Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency (CISA) is warning organizations that attackers continue to exploit the well known Pulse Secure VPN vulnerability tracked as CVE-2019-11510. The CVE-2019-11510 flaw in Pulse Connect Secure […]

    newssecurityaffairs.comJan 11, 2020, 6:57 AM
  • The U.S. Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency (CISA) has warned organizations that malicious hackers continue to exploit a widely known Pulse Secure VPN vulnerability.

    newswww.securityweek.comJan 10, 2020, 7:45 PM
  • On the last day of 2019, foreign exchange company Travelex was hit by cyber attackers wielding the Sodinokibi (aka REvil) ransomware. More than a week later, the company’s websites and online services are still offline despite the company’s remediation efforts. Current situation “Travelex has proactively taken steps to contain the spread of the ransomware, which has been successful. To date, the company can confirm that whilst there has been some data encryption, there is no … More →

    newswww.helpnetsecurity.comJan 8, 2020, 11:46 AM
  • A widely known vulnerability affecting an enterprise VPN product from Pulse Secure has been exploited by cybercriminals to deliver a piece of ransomware, a researcher has warned.

    newswww.securityweek.comJan 6, 2020, 4:22 PM
  • In April 2019, Pulse Secure published an advisory about a vulnerability in their software. In August, cybercriminals were massively scanning for…

    newswww.malwarebytes.comOct 17, 2019, 5:00 PM
  • NSA is warning of multiple state-sponsored cyberespionage groups exploiting enterprise VPN Flaws Last week, the UK’s National Cyber Security Centre (NCSC) reported that advanced persistent threat (APT) groups have been exploiting recently disclosed VPN vulnerabilities in enterprise VPN products in attacks in the wild. Threat actors leverage VPN vulnerabilities in Fortinet, Palo Alto Networks and Pulse Secure, to […]

    newssecurityaffairs.comOct 9, 2019, 8:37 PM
  • After the UK’s National Cyber Security Centre (NCSC) issued an alert , the National Security Agency (NSA) in the United States has also warned organizations that multiple state-sponsored threat actors have been exploiting the recently disclosed vulnerabilities affecting enterprise VPN products from Pulse Secure, Fortinet and Palo Alto Networks.

    newswww.securityweek.comOct 9, 2019, 12:07 PM
  • Virtual private networks (VPNs) are considered a safe remote access method. But are they? Known vulnerable VPN phone apps and enterprise solutions underscore the risk in using VPN applications. For example, an in-depth analysis of 283 mobile VPNs on the Google Play store by Australia’s Commonwealth Scientific and Industrial Research Organization found significant privacy and security […]

    newswww.csoonline.comOct 9, 2019, 10:00 AM
  • The UK’s National Cyber Security Centre (NCSC) warns of attacks exploiting recently disclosed VPN vulnerabilities in Fortinet, Palo Alto Networks and Pulse Secure According to the UK’s National Cyber Security Centre (NCSC), advanced persistent threat (APT) groups have been exploiting recently disclosed VPN vulnerabilities in enterprise VPN products in attacks in the wild. Threat actors […]

    newssecurityaffairs.comOct 6, 2019, 10:16 AM
  • Advanced persistent threat (APT) actors have been exploiting recently disclosed vulnerabilities affecting enterprise VPN products from Fortinet, Palo Alto Networks and Pulse Secure, the UK’s National Cyber Security Centre (NCSC) warns.

    newswww.securityweek.comOct 4, 2019, 6:12 PM
  • A new round of the weekly newsletter arrived! The best news of the week with Security Affairs Hi folk, let me inform you that I suspended the newsletter service, anyway I’ll continue to provide you a list of published posts every week through the blog. Once again thank you! 80 defendants charged with participating in […]

    newssecurityaffairs.comSep 1, 2019, 1:17 PM
  • Pulse Secure and Fortinet Take Steps to Protect Customers Against Attacks Exploiting Recently Disclosed Vulnerabilities

    newswww.securityweek.comAug 29, 2019, 10:44 AM
  • Attackers are taking advantage of recently released vulnerability details and PoC exploit code to extract private keys and user passwords from vulnerable Pulse Connect Secure SSL VPN and Fortigate SSL VPN installations. About the vulnerabilities Attackers have been scanning for and targeting two vulnerabilities: CVE-2019-11510, an arbitrary file reading vulnerability in Pulse Connect Secure CVE-2018-13379, a path traversal flaw in the FortiOS SSL VPN web portal. Both vulnerabilities can be exploited remotely by sending a … More →

    newswww.helpnetsecurity.comAug 26, 2019, 9:40 AM
  • BadPackets experts observed on August 22 a mass scanning activity targeting Pulse Secure “Pulse Connect Secure” VPN endpoints vulnerable to CVE-2019-11510. On August 22, BadPackets experts observed a mass scanning activity targeting Pulse Secure “Pulse Connect Secure” VPN endpoints vulnerable to CVE-2019-11510. Recently another popular cybersecurity expert, Kevin Beaumont, has also observed attackers attempting to exploit the CVE-2018-13379 in the FortiOS […]

    newssecurityaffairs.comAug 25, 2019, 5:25 PM
  • Hackers are exploiting recently disclosed flaws in enterprise virtual private network (VPN) products from Fortinet and Pulse Secure. The popular cybersecurity expert Kevin Beaumont has observed threat actors attempting to exploit the CVE-2018-13379 in the FortiOS SSL VPN web portal and CVE-2019-11510 flaw in Pulse Connect Secure. The CVE-2018-13379 is a path traversal vulnerability in the […]

    newssecurityaffairs.comAug 23, 2019, 4:02 PM
  • Recently disclosed vulnerabilities affecting enterprise virtual private network (VPN) products from Fortinet and Pulse Secure have been exploited in the wild, a researcher reported on Thursday.

    newswww.securityweek.comAug 22, 2019, 7:17 PM
  • Critical vulnerabilities in enterprise virtual private network (VPN) solutions from Palo Alto Networks, Fortinet and Pulse Secure allow attackers to infiltrate corporate networks, obtain sensitive information, and eavesdrop on communications, researchers warn.

    newswww.securityweek.comJul 25, 2019, 3:54 PM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

0 repository references · best confidence N/A · max 0 stars
No public PoC repositories have been matched yet.

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence