Back

MEDIUM

PAN-OS: OS Command Injection Vulnerability in the Web Interface

Published Dec 13, 2023

Description

An OS command injection vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to disrupt system processes and potentially execute arbitrary code with limited privileges on the firewall.

Affected products

Remediation

Vendor solution

This issue is fixed in PAN-OS 8.1.24-h1, PAN-OS 9.0.17, PAN-OS 9.1.12, PAN-OS 10.0.9, PAN-OS 10.1.3, and all later PAN-OS versions.

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner palo_alto
Published Dec 13, 2023
Updated Aug 2, 2024
Reserved Dec 13, 2023
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner palo_alto
Published Dec 13, 2023
Updated Aug 2, 2024
Exploited since n/a
EUVD-2023-59006