Impact
A command injection flaw in the PAN‑OS management plane lets an authenticated administrator run arbitrary operating‑system commands with root privileges, allowing full control over the firewall, configuration tampering, denial‑of‑service, or data exfiltration.
Affected Systems
The vulnerability affects PA‑Series and VM‑Series firewalls, Panorama appliances, and M‑Series devices running PAN‑OS versions 10.2.x, 11.1.x, 11.2.x, and 12.1.x. Older unsupported releases should be upgraded to a supported fixed version. Cloud NGFW and Prisma Access devices are not impacted.
Risk and Exploitability
The CVSS score of 6.0 denotes moderate severity, while the EPSS score of 1 % indicates a very low but non‑zero likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Successful exploitation requires valid administrator credentials with CLI access; limiting the MGT port to a small, privileged group and enforcing least‑privilege rules greatly reduces the risk.
OpenCVE Enrichment