PAN-OS: Remote code execution vulnerability in the PAN-OS SSH device management interface
Published Aug 23, 2019
9.8
CRITICALCVSS 3.1
EPSS 3.24%
Description
A remote code execution vulnerability in the PAN-OS SSH device management interface that can lead to unauthenticated remote users with network access to the SSH management interface gaining root access to PAN-OS. This issue affects PAN-OS 7.1 versions prior to 7.1.24-h1, 7.1.25; 8.0 versions prior to 8.0.19-h1, 8.0.20; 8.1 versions prior to 8.1.9-h4, 8.1.10; 9.0 versions prior to 9.0.3-h3, 9.0.4.
Affected products
-
- Version 7.1StatusaffectedConstraints<7.1.24-h1, 7.1.25
- Version 8.0StatusaffectedConstraints<8.0.19-h1, 8.0.20
- Version 8.1StatusaffectedConstraints<8.1.9-h4, 8.1.10
- Version 9.0StatusaffectedConstraints<9.0.3-h3, 9.0.4
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Palo Alto Networks | Pan-OS | n/a |
|
- ≤ 7.1.24
- ≥ 8.0.0 · ≤ 8.0.19
- ≥ 8.1.0 · ≤ 8.1.9
- ≥ 9.0.0 · ≤ 9.0.3
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
This issue has been resolved in PAN-OS 7.1.24-h1 and later, PAN-OS 8.0.19-h1 and later, PAN-OS 8.1.9-h4 and later, and PAN-OS 9.0.3-h3 and later.
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-10138 Advisory
- https://security.paloaltonetworks.com/CVE-2019-1581 x_refsource_CONFIRM
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-10138 | Advisory | |
| https://security.paloaltonetworks.com/CVE-2019-1581 | x_refsource_CONFIRM |
Change history (0)
No recorded changes yet.