Impact
A buffer overflow in the User‑ID Authentication Portal (Captive Portal) service lets an unauthenticated attacker send specially crafted packets that overflow a stack buffer and execute arbitrary code with root privileges on Palo Alto Networks PA‑Series and VM‑Series firewalls. The flaw can be triggered without authentication, giving the attacker full control over the device and the ability to compromise confidentiality, integrity, and availability.
Affected Systems
The vulnerability affects Palo Alto Networks PA‑Series and VM‑Series firewalls running PAN‑OS. Prisma Access, Cloud NGFW, and Panorama appliances are not impacted. No specific PAN‑OS version is listed, so operators should verify against vendor releases to ensure the bug is fixed.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity, and the EPSS score of 32% shows a moderate probability of exploitation. The vulnerability is listed in the CISA KEV catalog, signaling active exploitation. An attacker can exploit it via the network by sending malicious packets to the User‑ID Authentication Portal, without requiring authentication. The impact is root‑level code execution on the firewall.
OpenCVE Enrichment