Junglewise Threat Intelligence

CVE-2017-15944: Palo Alto Networks PAN-OS Remote Code Execution Vulnerability

CVE-2017-15944 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2022-08-18

Technologies: Palo Alto Networks PAN-OS. Vendors: Palo Alto Networks, Palo Alto Networks.

Executive brief

Palo Alto Networks PAN-OS contains multiple vulnerabilities in the management interface that, when chained, allow unauthenticated remote attackers to execute arbitrary code with root privileges. The vulnerability has been observed being exploited in the wild and is included in CISA's Known Exploited Vulnerabilities Catalog.

Affected products

  • Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, 8.0.x before 8.0.6

Timeline

  • 2017-12-13: disclosed: Initial public disclosure and security advisory release.
  • 2022-08-18: kev added: Added to CISA's Known Exploited Vulnerabilities Catalog.

Related threats