Expert found critical issues in Palo Alto PAN
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2017-15940 | The web interface packet capture management component in Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0 The web interface packet capture management component in Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 allows remote authenticated users to execute arbitrary code via unspecified vectors. NVD description · AI analysis pending | 9.8 | 5% |
| — | ||
| CVE-2017-15944 | Unauthenticated Remote Code Execution in Palo Alto Networks PAN-OS Palo Alto Networks PAN-OS contains a critical remote code execution flaw, driven by improper input validation and memory-safety weaknesses (CWE-20, CWE-119), that is reachable through the firewall's management interface. An unauthenticated remote attacker can trigger the flaw via crafted requests to the management interface, and successful exploitation grants the ability to execute arbitrary code with high impact on confidentiality, integrity, and availability (CVSS 3.1: 9.8). Only PAN-OS firewalls whose management interface is reachable from untrusted networks, such as the internet, are practically exploitable. Organizations running PAN-OS before the fixed releases (6.1.19, 7.0.19, 7.1.14, 8.0.6) are affected. The flaw is under active exploitation: it was added to CISA's Known Exploited Vulnerabilities Catalog on 2022-08-18, carries a 98.3% EPSS probability of exploitation within 30 days, and public proof-of-concept exploits are available on Exploit-DB. Do: Upgrade PAN-OS to 6.1.19 or later (6.1.x), 7.0.19 or later (7.0.x), 7.1.14 or later (7.1.x), or 8.0.6 or later (8.0.x) per vendor instructions. Until patched, restrict access to the management interface to trusted administrative networks only and verify it is not exposed to the internet. Review logs for suspicious activity against the management interface, since this flaw is listed in CISA's KEV catalog and is being actively exploited. | 9.8 | 98% | KEV PoC ×2 |
| largetens of thousands of internet-exposed PAN-OS management interfaces (of a firewall install base well over 100,000 devices) |
Full article393 words · extracted from securityaffairs.com · click to collapse
Pierluigi Paganini
December 18, 2017

Palo Alto Networks released security updates for its PAN-OS security platform that address critical and high severity vulnerabilities
Last week, Palo Alto Networks released security updates for its PAN-OS security platform that address critical and high severity vulnerabilities that can be exploited by a remote and unauthenticated for remote code execution and command injection.
The critical issue, tracked as CVE-2017-15944, is a combination of flaws that affect the management interface.
PAN-OS 6.1.18, 7.0.18, 7.1.13, 8.0.5 and earlier versions are affected by the issue that was addressed by security updates included in PAN-OS 6.1.19, 7.0.19, 7.1.14 and 8.0.6.
Palo Alto Network also released vulnerability signatures to block the attacks that exploit this issue.
The set of vulnerability was discovered in July by Philip Pettersson that published a security advisory on SecList. Pettersson has found three vulnerabilities (a partial authentication bypass, an arbitrary directory creation issue, and a command injection bug) that can be chained to allow an unauthenticated attacker to execute arbitrary code with root privileges through the vulnerable web interface.
“This is a public advisory for CVE-2017-15944 which is a remote root code execution bug in Palo Alto Networks firewalls. Three separate bugs can be used together to remotely execute commands as root through the web management interface without authentication on: PAN-OS 6.1.18 and earlier, PAN-OS 7.0.18 and earlier, PAN-OS 7.1.13 and earlier, PAN-OS 8.0.5 and earlier.” reads the advisory.
Palo Alto Networks notified customers the vulnerability informing them to avoid exposing the web interface of its devices to the Internet.
The security updated for PAN-OS also address a high severity flaw in the web interface packet capture management component tracked as CVE-2017-15940.
The flaw can be exploited by an authenticated attacker to inject arbitrary commands.
Affected products are PAN-OS 6.1.18 and earlier, PAN-OS 7.0.18 and earlier, PAN-OS 7.1.13 and earlier, PAN-OS 8.0.6 and earlier.
“This issue affects the management interface of the device and is strongly mitigated by following best practices for the isolation of management interfaces for security appliances. We recommend that the management interface be isolated and strictly limited only to security administration personnel through either network segmentation or using the IP access control list restriction feature within PAN-OS.” reads the advisory.
| [adrotate banner=”9″] | [adrotate banner=”12″] |
(Security Affairs –Palo Alto Networks Security Platform, hacking)
[adrotate banner=”5″]
[adrotate banner=”13″]
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/66860/hacking/pan-os-security-platform-flaws.html