ZeroHour

CVE-2019-1579

KEV ransomware PoC large

Format String RCE in Palo Alto Networks PAN-OS GlobalProtect Portal/Gateway

CISA: Palo Alto Networks PAN-OS Remote Code Execution Vulnerability

CVSS 3.1
8.1 high
EPSS
46%p99
Published
()
KEV added
AI analysis

CVE-2019-1579 is a remote code execution vulnerability (CWE-134, format string) in Palo Alto Networks PAN-OS that is exposed on devices where the GlobalProtect Portal or GlobalProtect Gateway interface is enabled. An attacker can trigger it remotely by sending specially crafted format-string input to the network-facing GlobalProtect portal or gateway interface. Successful exploitation allows arbitrary code execution on the firewall, giving the attacker control of the device and a foothold into the protected network. Any organization running PAN-OS with the GlobalProtect Portal or Gateway interface enabled is affected; deployments without those interfaces enabled are not exposed to this flaw. Exploitation is confirmed: the vulnerability is in CISA's KEV (added 2022-01-10) with known ransomware use, and EPSS assigns a 46.2% probability of exploitation within 30 days (99th percentile), although no public PoC is catalogued.

What to do: Upgrade PAN-OS per Palo Alto Networks' security advisory, as required by CISA's KEV required action; first inventory devices with the GlobalProtect Portal or Gateway interface enabled and prioritize internet-facing ones. Until patched, restrict or firewall access to the GlobalProtect interfaces, and hunt for signs of compromise given the known ransomware association.

Affected
Palo Alto Networks PAN-OS
Estimated exposure
largetens of thousands of internet-exposed GlobalProtect portals/gateways (likely more including internally deployed gateways) — Public internet scans have historically shown tens of thousands of exposed GlobalProtect portal/gateway services, and PAN-OS firewalls have a large enterprise installed base, but only devices with the portal or gateway interface enabled…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Remote Code Execution in PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11-h1 and earlier, and PAN-OS 8.1.2 and earlier with GlobalProtect Portal or GlobalProtect Gateway Interface enabled may allow an unauthenticated remote attacker to execute arbitrary code.

CISA Known Exploited Vulnerability
Affected
Palo Alto Networks PAN-OS
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
paloaltonetworks
Products
pan-os
Weakness
CWE-134
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news