PT-2026-48488 · Palo Alto Networks · Vm Series+3
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
PAN-OS versions 10.2 (affected versions not specified)
PAN-OS versions 11.1 (affected versions not specified)
PAN-OS versions 11.2 (affected versions not specified)
PAN-OS versions 12.1 (affected versions not specified)
Description
A command injection issue in PAN-OS software allows an authenticated administrator to bypass system restrictions and execute arbitrary commands with root privileges. This can be achieved through the CLI or the web management interface. The issue affects PA-Series and VM-Series firewalls, as well as Panorama virtual and M-Series appliances.
Recommendations
Update PAN-OS version 10.2 to the patched release.
Update PAN-OS version 11.1 to the patched release.
Update PAN-OS version 11.2 to the patched release.
Update PAN-OS version 12.1 to the patched release.
Restrict CLI access to a limited group of administrators.
Restrict access to the management web interface to trusted internal IP addresses.
Fix
LPE
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pa-Series
Pan-Os
Panorama
Vm Series