Executive brief
A remote code execution vulnerability exists in Palo Alto Networks PAN-OS when the GlobalProtect Portal or GlobalProtect Gateway Interface is enabled. An unauthenticated remote attacker can exploit this to execute arbitrary code on the affected system.
Affected products
- Palo Alto Networks PAN-OS 7.1.18 and earlier, 8.0.11-h1 and earlier, 8.1.2 and earlier
Timeline
- 2019-07-17: disclosed: Public blog post detailing the exploit case study.
- 2022-01-10: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.