PT-2026-56586 · Palo Alto Networks · Pan-Os
CVSS v2.0
8.5
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
PAN-OS versions prior to 12.1.8
PAN-OS versions prior to 11.2.13
PAN-OS versions prior to 11.1.16
PAN-OS versions prior to 10.2.18-h8
Description
A command injection issue exists in the management plane of the software, specifically within the Command Line Interface (CLI). This allows an authenticated administrator to break out of the CLI and execute arbitrary operating system commands with root privileges on the underlying system. The risk is reduced when CLI access is restricted to a limited group of administrators.
Recommendations
Update to version 12.1.8 or later.
Update to version 11.2.13 or later.
Update to version 11.1.16 or later.
Update to version 10.2.18-h8 or later.
As a temporary mitigation, apply Threat ID 510036 (content version 9122-10145 or later) for users with a Threat Prevention subscription who are decrypting inbound management traffic.
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pan-Os