Description
A remote code execution vulnerability in the PAN-OS SSH device management interface that can lead to unauthenticated remote users with network access to the SSH management interface gaining root access to PAN-OS. This issue affects PAN-OS 7.1 versions prior to 7.1.24-h1, 7.1.25; 8.0 versions prior to 8.0.19-h1, 8.0.20; 8.1 versions prior to 8.1.9-h4, 8.1.10; 9.0 versions prior to 9.0.3-h3, 9.0.4.
Published: 2019-08-23
Score: 9.8 Critical
EPSS: 2.7% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

This issue has been resolved in PAN-OS 7.1.24-h1 and later, PAN-OS 8.0.19-h1 and later, PAN-OS 8.1.9-h4 and later, and PAN-OS 9.0.3-h3 and later.


Vendor Workaround

This issue affects the SSH management interface of PAN-OS and is strongly mitigated by following best practices for securing the PAN-OS management interfaces. Our best practices guidelines reduce the exposure of device management interfaces to potential attacker.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2019-10138 A remote code execution vulnerability in the PAN-OS SSH device management interface that can lead to unauthenticated remote users with network access to the SSH management interface gaining root access to PAN-OS. This issue affects PAN-OS 7.1 versions prior to 7.1.24-h1, 7.1.25; 8.0 versions prior to 8.0.19-h1, 8.0.20; 8.1 versions prior to 8.1.9-h4, 8.1.10; 9.0 versions prior to 9.0.3-h3, 9.0.4.
History

Tue, 17 Sep 2024 01:00:00 +0000

Type Values Removed Values Added
Title PAN-OS: Remote code execution vulnerability in the PAN-OS SSH device management interface PAN-OS: Remote code execution vulnerability in the PAN-OS SSH device management interface

Subscriptions

Paloaltonetworks Pan-os
cve-icon MITRE

Status: PUBLISHED

Assigner: palo_alto

Published:

Updated: 2024-09-17T00:56:45.260Z

Reserved: 2018-12-06T00:00:00.000Z

Link: CVE-2019-1581

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-08-23T18:15:11.503

Modified: 2024-11-21T04:36:51.193

Link: CVE-2019-1581

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses