Impact
The vulnerability allows an authenticated administrator to inject arbitrary shell commands through the CLI when a device is configured with a Luna hardware security module. By exploiting a flaw in command parsing, the attacker can bypass system restrictions and execute commands with root privileges, which effectively turns the system into a fully compromised host for the attacker.
Affected Systems
Only PAN‑OS devices are affected. All versions from 11.1.0 through 12.2.2 that have not been patched to the recommended releases are vulnerable. The recommended fix is to upgrade to the minimum fixed versions listed for each release branch. Panorama, Cloud NGFW, and Prisma Access are not impacted.
Risk and Exploitability
The CVSS score of 4.0 indicates a moderate impact. There is no publicly available exploit and the EPSS score is not provided, so the likelihood of exploitation is unknown. The flaw requires the attacker to be an authenticated administrator with CLI access and an active Luna HSM configuration, which limits the attack surface but still presents a significant risk. Until the vulnerable software is upgraded, restricting CLI access to a small, trusted group reduces the risk.
OpenCVE Enrichment