vendor:
PAN-OS
by:
UnD3sc0n0c1d0
7.5
CVSS
HIGH
Remote Code Execution
78
CWE
Product Name: PAN-OS
Affected Version From: <10.0.1
Affected Version To: 9.0.10
Patch Exists: YES
Related CWE: CVE-2020-2038
CPE: a:paloaltonetworks:pan-os
Platforms Tested: PAN-OS 10.0 - Parrot OS
2022
PAN-OS 10.0 – Remote Code Execution (RCE) (Authenticated)
An OS Command Injection vulnerability in the PAN-OS management interface that allows authenticated administrators to execute arbitrary OS commands with root privileges.
Mitigation:
Upgrade to PAN-OS version 10.0.1 or higher, 9.1.4 or higher, or 9.0.10 or higher.