ZeroHour

CVE-2017-15944

KEV PoC ×2large

Unauthenticated Remote Code Execution in Palo Alto Networks PAN-OS

CISA: Palo Alto Networks PAN-OS Remote Code Execution Vulnerability

CVSS 3.1
9.8 critical
EPSS
98%p100
Published
()
KEV added
AI analysis

Palo Alto Networks PAN-OS contains a critical remote code execution flaw, driven by improper input validation and memory-safety weaknesses (CWE-20, CWE-119), that is reachable through the firewall's management interface. An unauthenticated remote attacker can trigger the flaw via crafted requests to the management interface, and successful exploitation grants the ability to execute arbitrary code with high impact on confidentiality, integrity, and availability (CVSS 3.1: 9.8). Only PAN-OS firewalls whose management interface is reachable from untrusted networks, such as the internet, are practically exploitable. Organizations running PAN-OS before the fixed releases (6.1.19, 7.0.19, 7.1.14, 8.0.6) are affected. The flaw is under active exploitation: it was added to CISA's Known Exploited Vulnerabilities Catalog on 2022-08-18, carries a 98.3% EPSS probability of exploitation within 30 days, and public proof-of-concept exploits are available on Exploit-DB.

What to do: Upgrade PAN-OS to 6.1.19 or later (6.1.x), 7.0.19 or later (7.0.x), 7.1.14 or later (7.1.x), or 8.0.6 or later (8.0.x) per vendor instructions. Until patched, restrict access to the management interface to trusted administrative networks only and verify it is not exposed to the internet. Review logs for suspicious activity against the management interface, since this flaw is listed in CISA's KEV catalog and is being actively exploited.

Affected
paloaltonetworks pan-osbefore 6.1.19
paloaltonetworks pan-os7.0.x before 7.0.19
paloaltonetworks pan-os7.1.x before 7.1.14
paloaltonetworks pan-os8.0.x before 8.0.6
Estimated exposure
largetens of thousands of internet-exposed PAN-OS management interfaces (of a firewall install base well over 100,000 devices) — PAN-OS firewalls are widely deployed by enterprises and service providers, and public internet scans have historically shown tens of thousands of PAN-OS management interfaces exposed online, which is the subset actually exploitable by this…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 allows remote attackers to execute arbitrary code via vectors involving the management interface.

CISA Known Exploited Vulnerability
Affected
Palo Alto Networks PAN-OS
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
paloaltonetworks
Products
pan-os
Weakness
CWE-20, CWE-119
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news