Impact
Palo Alto Networks PAN‑OS software contains multiple command injection flaws that allow an authenticated administrator with CLI or Web UI access to bypass normal security restrictions and execute arbitrary operating‑system commands as the root user. The vulnerability leverages improperly sanitized input, enabling the attacker to run any shell commands and potentially take full control of the device. It is classified as CWE‑78: Improper Neutralization of Input during OS Command Injection.
Affected Systems
The flaw applies to PAN‑OS running on PA‑Series, VM‑Series, Panorama (virtual and M‑Series) firewalls. Specific affected versions are outlined in the vendor’s advisory: for PAN‑OS 12.1.5–12.1.6 upgrade to 12.1.7 or later; for 12.1.2–12.1.4‑h* upgrade to 12.1.4‑h5 or 12.1.7; for 12.1.4 and earlier upgrade to the latest supported release. Similar patch guidelines exist for PAN‑OS 11.x and 10.x releases. Cloud NGFW and Prisma Access are not affected.
Risk and Exploitability
The vulnerability carries a CVSS score of 5.7, indicating a moderate risk. No EPSS value is published, and the issue is not listed in CISA’s KEV catalog, suggesting no widespread exploitation yet. However, the requirement of authenticated admin access means the attacker must compromise or obtain privileged credentials, which is a common attack scenario in large organizations. Once accessed, the attacker can run arbitrary root commands, fully compromising device confidentiality, integrity, and availability. Therefore, mitigation should be performed promptly.
OpenCVE Enrichment