Free and open-source vulnerability scanner

Mageni eases for you the vulnerability scanning, assessment, and management process. It is free and open-source.

Install Now

Available for macOS, Windows, and Linux

App screenshot

Palo Alto PAN-OS PAN-SA-2016-0003

Information

Severity

Severity

Critical

Family

Family

Palo Alto PAN-OS Local Security Checks

CVSSv2 Base

CVSSv2 Base

10.0

CVSSv2 Vector

CVSSv2 Vector

AV:N/AC:L/Au:N/C:C/I:C/A:C

Solution Type

Solution Type

Vendor Patch

Created

Created

8 years ago

Modified

Modified

5 years ago

Summary

Palo Alto Networks PAN-OS implements an API to enable programmatic device configuration and administration of the device. An issue was identified where the management API incorrectly parses input to a specific API call, leading to execution of arbitrary OS commands without authentication via the management interface.

Affected Software

Affected Software

PAN-OS releases 5.0.17, 6.0.12, 6.1.9, 7.0.4 and prior

Detection Method

Detection Method

Checks if a vulnerable version is present on the target host.

Solution

Solution

Update to PAN-OS releases 5.0.18, 6.0.13, 6.1.10 and 7.0.5 and newer

Common Vulnerabilities and Exposures (CVE)