
CVE-2019-11510 Pulse Secure: Pre-Auth Credential Theft
CVE-2019-11510 is a pre-authentication arbitrary file read vulnerability in Pulse Connect Secure VPN appliances. An unauthenticated attacker can retrieve the VPN's configuration file and stored credentials, including plaintext passwords and cached Active Directory credentials, from any affected device reachable on the internet. Widely exploited by ransomware groups, APTs, and credential brokers.
