CVE-2019-11543
Summary
| CVE | CVE-2019-11543 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-04-26 02:29:00 UTC |
| Updated | 2023-03-24 17:49:00 UTC |
| Description | XSS exists in the admin web console in Pulse Secure Pulse Connect Secure (PCS) 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, and 8.1RX before 8.1R15.1 and Pulse Policy Secure 9.0RX before 9.0R3.2, 5.4RX before 5.4R7.1, and 5.2RX before 5.2R12.1. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Pulsesecure | Pulse Connect Secure | 8.1 | All | All | All |
| Application | Pulsesecure | Pulse Connect Secure | 8.1r1.0 | All | All | All |
| Application | Pulsesecure | Pulse Connect Secure | 8.1rx | All | All | All |
| Application | Pulsesecure | Pulse Connect Secure | 8.3 | All | All | All |
| Application | Pulsesecure | Pulse Connect Secure | 8.3rx | All | All | All |
| Application | Pulsesecure | Pulse Connect Secure | 9.0r1 | All | All | All |
| Application | Pulsesecure | Pulse Connect Secure | 9.0r2 | All | All | All |
| Application | Pulsesecure | Pulse Connect Secure | 9.0r2.1 | All | All | All |
| Application | Pulsesecure | Pulse Connect Secure | 9.0r3 | All | All | All |
| Application | Pulsesecure | Pulse Connect Secure | 9.0r3.1 | All | All | All |
| Application | Pulsesecure | Pulse Connect Secure | 9.0r3.2 | All | All | All |
| Application | Pulsesecure | Pulse Connect Secure | 9.0rx | All | All | All |
| Application | Pulsesecure | Pulse Connect Secure | 8.1 | All | All | All |
| Application | Pulsesecure | Pulse Connect Secure | 8.1r1.0 | All | All | All |
| Application | Pulsesecure | Pulse Connect Secure | 8.1rx | All | All | All |
| Application | Pulsesecure | Pulse Connect Secure | 8.3 | All | All | All |
| Application | Pulsesecure | Pulse Connect Secure | 8.3rx | All | All | All |
| Application | Pulsesecure | Pulse Connect Secure | 9.0r1 | All | All | All |
| Application | Pulsesecure | Pulse Connect Secure | 9.0r2 | All | All | All |
| Application | Pulsesecure | Pulse Connect Secure | 9.0r2.1 | All | All | All |
| Application | Pulsesecure | Pulse Connect Secure | 9.0r3 | All | All | All |
| Application | Pulsesecure | Pulse Connect Secure | 9.0r3.1 | All | All | All |
| Application | Pulsesecure | Pulse Connect Secure | 9.0r3.2 | All | All | All |
| Application | Pulsesecure | Pulse Connect Secure | 9.0rx | All | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 5.2r1.0 | All | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 5.2r10.0 | All | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 5.2r11.0 | All | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 5.2r2.0 | All | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 5.2r3.0 | All | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 5.2r3.2 | All | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 5.2r4.0 | All | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 5.2r5.0 | All | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 5.2r6.0 | All | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 5.2r7.0 | All | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 5.2r7.1 | All | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 5.2r8.0 | All | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 5.2r9.0 | All | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 5.2r9.1 | All | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 5.2rx | All | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 5.4r1 | All | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 5.4r2 | All | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 5.4r2.1 | All | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 5.4r3 | All | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 5.4r4 | All | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 5.4r5 | All | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 5.4r5.2 | All | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 5.4r6 | All | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 5.4r6.1 | All | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 5.4r7 | All | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 5.4rx | All | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 9.0r1 | All | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 9.0r2 | All | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 9.0r2.1 | All | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 9.0r3 | All | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 9.0r3.1 | All | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 9.0rx | All | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 5.2r1.0 | All | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 5.2r10.0 | All | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 5.2r11.0 | All | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 5.2r2.0 | All | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 5.2r3.0 | All | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 5.2r3.2 | All | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 5.2r4.0 | All | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 5.2r5.0 | All | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 5.2r6.0 | All | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 5.2r7.0 | All | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 5.2r7.1 | All | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 5.2r8.0 | All | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 5.2r9.0 | All | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 5.2r9.1 | All | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 5.2rx | All | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 5.4r1 | All | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 5.4r2 | All | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 5.4r2.1 | All | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 5.4r3 | All | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 5.4r4 | All | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 5.4r5 | All | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 5.4r5.2 | All | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 5.4r6 | All | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 5.4r6.1 | All | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 5.4r7 | All | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 5.4rx | All | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 9.0r1 | All | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 9.0r2 | All | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 9.0r2.1 | All | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 9.0r3 | All | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 9.0r3.1 | All | All | All |
| Application | Pulsesecure | Pulse Policy Secure | 9.0rx | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| VU#927237 - Multiple vulnerabilities in Pulse Secure VPN | CERT-VN | www.kb.cert.org | |
| Pulse Connect Secure and Pulse Policy Secure Multiple Security Vulnerabilities | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| Public KB - SA44101 - 2019-04: Out-of-Cycle Advisory: Multiple vulnerabilities resolved in Pulse Connect Secure / Pulse Policy Secure 9.0RX | MISC | kb.pulsesecure.net | Vendor Advisory |
| Public KB - SA44101 - 2019-04: Out-of-Cycle Advisory: Multiple vulnerabilities resolved in Pulse Connect Secure / Pulse Policy Secure 9.0RX | CONFIRM | kb.pulsesecure.net | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.