An OS command injection vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to disrupt system processes and potentially execute arbitrary code with limited privileges on the firewall.

Project Subscriptions

Vendors Products
Paloaltonetworks Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2023-59006 An OS command injection vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to disrupt system processes and potentially execute arbitrary code with limited privileges on the firewall.
Fixes

Solution

This issue is fixed in PAN-OS 8.1.24-h1, PAN-OS 9.0.17, PAN-OS 9.1.12, PAN-OS 10.0.9, PAN-OS 10.1.3, and all later PAN-OS versions.


Workaround

This issue requires the attacker to have authenticated access to the PAN-OS web interface. You can mitigate the impact of this issue by following the Best Practices for Securing Administrative Access in the PAN-OS technical documentation at https://docs.paloaltonetworks.com/best-practices.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: palo_alto

Published:

Updated: 2024-08-02T08:42:08.431Z

Reserved: 2023-12-13T17:27:27.372Z

Link: CVE-2023-6795

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2023-12-13T19:15:10.537

Modified: 2024-11-21T08:44:34.700

Link: CVE-2023-6795

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses