PT-2021-4803 · Palo Alto Networks · Pan-Os

Cj

·

Published

2021-11-10

·

Updated

2021-11-15

·

CVE-2021-3060

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions PAN-OS versions earlier than 8.1.20-h1 PAN-OS versions earlier than 9.0.14-h3 PAN-OS versions earlier than 9.1.11-h2 PAN-OS versions earlier than 10.0.8 PAN-OS versions earlier than 10.1.3
Description An OS command injection vulnerability in the Simple Certificate Enrollment Protocol (SCEP) feature of PAN-OS software allows an unauthenticated network-based attacker with specific knowledge of the firewall configuration to execute arbitrary code with root user privileges. The attacker must have network access to the GlobalProtect interfaces to exploit this issue.
Recommendations For PAN-OS 8.1, update to version 8.1.20-h1 or later. For PAN-OS 9.0, update to version 9.0.14-h3 or later. For PAN-OS 9.1, update to version 9.1.11-h2 or later. For PAN-OS 10.0, update to version 10.0.8 or later. For PAN-OS 10.1, update to version 10.1.3 or later. As a temporary workaround, consider restricting access to the GlobalProtect interfaces until a patch is available.

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-05528
CVE-2021-3060

Affected Products

Pan-Os