PT-2021-18777 · Palo Alto Networks · Pan-Os+1

Ben Nott

+1

·

Published

2021-11-10

·

Updated

2021-11-15

·

CVE-2021-3061

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions PAN-OS versions earlier than 8.1.20-h1 PAN-OS versions earlier than 9.0.14-h3 PAN-OS versions earlier than 9.1.11-h2 PAN-OS versions earlier than 10.0.8 PAN-OS versions earlier than 10.1.3 Prisma Access 2.1 firewalls
Description An OS command injection vulnerability in the Palo Alto Networks PAN-OS command line interface (CLI) enables an authenticated administrator with access to the CLI to execute arbitrary OS commands to escalate privileges.
Recommendations For PAN-OS 8.1 versions earlier than 8.1.20-h1, update to PAN-OS 8.1.20-h1 or later. For PAN-OS 9.0 versions earlier than 9.0.14-h3, update to PAN-OS 9.0.14-h3 or later. For PAN-OS 9.1 versions earlier than 9.1.11-h2, update to PAN-OS 9.1.11-h2 or later. For PAN-OS 10.0 versions earlier than 10.0.8, update to PAN-OS 10.0.8 or later. For PAN-OS 10.1 versions earlier than 10.1.3, update to PAN-OS 10.1.3 or later. As a temporary workaround for Prisma Access 2.1 firewalls, consider restricting access to the CLI until a patch is available.

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-3061

Affected Products

Pan-Os
Prisma Access