Rapid7 Vulnerability & Exploit Database

PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect

Free InsightVM Trial No Credit Card Necessary
Watch Demo See how it all works
Back to Search

PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect

Severity
4
CVSS
(AV:L/AC:M/Au:N/C:P/I:P/A:P)
Published
04/12/2024
Created
04/15/2024
Added
04/15/2024
Modified
04/22/2024

Description

A command injection as a result of arbitrary file creation vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software for specific PAN-OS versions and distinct feature configurations may enable an unauthenticated attacker to execute arbitrary code with root privileges on the firewall. Cloud NGFW, Panorama appliances, and Prisma Access are not impacted by this vulnerability.

Solution(s)

  • palo-alto-networks-pan-os-upgrade-10-2
  • palo-alto-networks-pan-os-upgrade-11-0
  • palo-alto-networks-pan-os-upgrade-11-1

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;