Back

HIGH KEV Used in ransomware campaigns

Remote Code Execution in PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11-h1 and earlier, and PAN-OS 8.1.2 and earlier with GlobalProtect Portal or GlobalProtect Gateway Interface enabled may allow an unauthenticated remote attacker to execute arbitrary code

Published Jul 19, 2019 ·Due Jul 10, 2022

Description

Remote Code Execution in PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11-h1 and earlier, and PAN-OS 8.1.2 and earlier with GlobalProtect Portal or GlobalProtect Gateway Interface enabled may allow an unauthenticated remote attacker to execute arbitrary code.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (5)

Change history (3)
  1. CISA ADP
    • SSVC automatable changed from yes to no
  2. CISA ADP
    • SSVC automatable changed from no to yes
  3. CISA ADP
    • SSVC automatable changed from yes to no
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner palo_alto
Published Jul 19, 2019
Updated Oct 2, 2026
Reserved Dec 6, 2018
CISA Vulnrichment
Updated Oct 1, 2026
NVD
Status Analyzed
Modified Oct 2, 2026
Red Hat
Severity n/a
Public date n/a