PT-2017-14301 · Palo Alto Networks · Pan-Os+1
Philip Pettersson
·
Published
2017-12-06
·
Updated
2025-10-10
·
CVE-2017-15944
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Palo Alto Networks PAN-OS versions prior to 6.1.19
Palo Alto Networks PAN-OS versions 7.0.x prior to 7.0.19
Palo Alto Networks PAN-OS versions 7.1.x prior to 7.1.14
Palo Alto Networks PAN-OS versions 8.0.x prior to 8.0.6
Description
The issue allows remote attackers to execute arbitrary code via vectors involving the management interface. This can be achieved through the exploitation of a combination of unrelated vulnerabilities in the management interface of the device, allowing an attacker to remotely execute code on PAN-OS or Panorama in the context of the highest privileged user.
Recommendations
For versions prior to 6.1.19, update to version 6.1.19 or later.
For versions 7.0.x prior to 7.0.19, update to version 7.0.19 or later.
For versions 7.1.x prior to 7.1.14, update to version 7.1.14 or later.
For versions 8.0.x prior to 8.0.6, update to version 8.0.6 or later.
As a temporary workaround, consider restricting access to the management interface until a patch is available.
Exploit
Fix
RCE
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Pan-Os
Panorama