Palo Alto Networks PAN-OS Management Interface OS Command Injection Vulnerability
Palo Alto Networks · PAN-OS
Date added (CISA)
2024-11-18
Remediation due
2024-12-09
Known ransomware use
Yes
Remediation priority
P1 — known ransomware use · past CISA due date
Description
Palo Alto Networks PAN-OS contains an OS command injection vulnerability that allows for privilege escalation through the web-based management interface for several PAN products, including firewalls and VPN concentrators.