HomePentest-Tools.com Logo

Palo Alto - Remote Code Execution (CVE-2017-15944)

Severity
CVSSv3 Score
9.8
Exploitable with Sniper
No
Vulnerability description

Palo Alto server is affected by a Remote Code Execution through a Path Traversal vulnerability, located in the /public/plugins/ endpoint. The root cause of this vulnerability consists in improper path normalization. Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 allows remote attackers to execute arbitrary code via vectors involving the management interface.

Risk description

The risk exists that a remote unauthenticated attacker can fully compromise the server to steal confidential information, install ransomware, or pivot to the internal network.

Recommendation

Upgrade Palo Alto to the latest version.

Detectable with
Network Scanner
Vuln date
Nov 2021
Published at
Updated at
Software Type
Monitoring system
Vendor
Palo Alto
Product
PanOS
Codename
Not available