Impact
A command injection flaw in Palo Alto Networks PAN‑OS allows an authenticated administrator to bypass system restrictions and execute arbitrary commands with root privileges. The flaw can be triggered from either the CLI or the Web UI, enabling an attacker to compromise the entire device by running any command or script. The vulnerability falls under CWE‑78, indicating that it involves operating system command execution based on insufficient input validation.
Affected Systems
The issue affects PAN‑OS deployments on PA‑Series, VM‑Series, Panorama (virtual and M‑Series) firewalls. Vulnerable software includes 12.1.5 through 12.1.6, 12.1.2‑12.1.4‑h*, 11.2.0‑11.2.10‑h*, 11.1.0‑11.1.14, and 10.2.0‑10.2.18‑h*. Cloud NGFW and Prisma Access are not affected.
Risk and Exploitability
The CVSS score of 5.7 indicates a moderate risk level. No EPSS data is available and KEV status is "not listed," suggesting a low to moderate exploitation likelihood. Because the vulnerability requires administrative credentials, it can be highly damaging if an attacker already has or can obtain such access. Restricting CLI and Web UI access to a narrow group of trusted administrators and limiting management interface exposure to internal IPs significantly reduces exploitation potential. However, the fastest way to eliminate the risk is to apply the vendor‑issued patch.
OpenCVE Enrichment