PT-2012-6289 · Palo Alto Networks · Pan-Os

Published

2012-04-27

·

Updated

2020-02-17

·

CVE-2012-6600

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Palo Alto Networks PAN-OS versions 3.0.x and earlier are not affected, but the following are: PAN-OS versions 4.0.0 through 4.0.8 PAN-OS versions 4.1.0 through 4.1.1
Description The device-management command-line interface allows remote authenticated users to execute arbitrary commands, which can result in total compromise of the device. This issue can be exploited by injecting arbitrary shell commands using the device management command line interface.
Recommendations For PAN-OS versions 4.0.0 through 4.0.8, update to version 4.0.9 or later. For PAN-OS versions 4.1.0 through 4.1.1, update to version 4.1.2 or later.

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2012-6600

Affected Products

Pan-Os