PT-2017-14301 · Palo Alto Networks · Pan-Os+1
Philip Pettersson
·
Publicado
2017-12-06
·
Atualizado
2025-10-10
·
CVE-2017-15944
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Palo Alto Networks PAN-OS versions prior to 6.1.19
Palo Alto Networks PAN-OS versions 7.0.x prior to 7.0.19
Palo Alto Networks PAN-OS versions 7.1.x prior to 7.1.14
Palo Alto Networks PAN-OS versions 8.0.x prior to 8.0.6
Description
The issue allows remote attackers to execute arbitrary code via vectors involving the management interface. This can be achieved through the exploitation of a combination of unrelated vulnerabilities in the management interface of the device, allowing an attacker to remotely execute code on PAN-OS or Panorama in the context of the highest privileged user.
Recommendations
For versions prior to 6.1.19, update to version 6.1.19 or later.
For versions 7.0.x prior to 7.0.19, update to version 7.0.19 or later.
For versions 7.1.x prior to 7.1.14, update to version 7.1.14 or later.
For versions 8.0.x prior to 8.0.6, update to version 8.0.6 or later.
As a temporary workaround, consider restricting access to the management interface until a patch is available.
Exploit
Correção
RCE
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Pan-Os
Panorama