Impact
A proven privilege‑escalation flaw in Palo Alto Networks PAN‑OS allows an authenticated administrator who can access the device’s command line interface to execute commands with root privileges. The flaw falls under CWE‑862 (Missing Authorization) and permits the attacker to modify system configuration, install or remove packages, and otherwise take full control of the firewall or Panorama device.
Affected Systems
Affected products are PAN‑OS firmware on PA‑Series, VM‑Series, Panorama (virtual and M‑Series). Vulnerable versions include PAN‑OS 10.2 (10.2.0‑10.2.18‑h*), 11.1 (11.1.0‑11.1.13‑h*), 11.2 (11.2.0‑11.2.10‑h*), and 12.1 (12.1.2‑12.1.4‑h*). Cloud NGFW and Prisma Access are not impacted.
Risk and Exploitability
The CVSS score is 5.6 indicating moderate severity. EPSS data is unavailable and the issue is not cataloged in CISA KEV. Exploitation requires an authenticated CLI session, so restricting CLI access or limiting it to trusted internal IPs mitigates the risk. If the management interface is exposed, an attacker who gains administrator credentials can leverage the flaw to obtain root access on the device.
OpenCVE Enrichment