Impact
The User-ID Terminal Server Agent in Palo Alto Networks PAN-OS has multiple buffer‑overflow defects that an unauthenticated attacker with network access can exploit by sending specially crafted packets. The resulting overflow can crash the agent, causing a denial of service, or under specific circumstances can allow execution of arbitrary code, thereby compromising the confidentiality, integrity, or availability of the device.
Affected Systems
Affected releases include PAN‑OS 12.1.2 through 12.1.7, 11.2.0 through 11.2.12, 11.1.0 through 11.1.15, and 10.2.0 through 10.2.18, as well as Prisma Access versions 11.2.0‑11.2.7 and 10.2.0‑10.2.10. The Cloud NGFW is not impacted, and Panorama is not affected.
Risk and Exploitability
The CVSS score of 4.8 indicates moderate severity, and the EPSS score of < 1 % shows a very low but non‑zero exploitation probability. The vulnerability is network‑based, requires no authentication, and requires an attacker to reach the TSA service. Because the attack can lead to arbitrary code execution if successful, the risk remains significant, especially on systems that expose the agent to untrusted traffic. Restricting TSA connectivity to trusted internal IP ranges reduces exposure considerably. The vulnerability is not listed in the CISA KEV catalog, indicating no confirmed exploitation in the wild.
OpenCVE Enrichment