Palo Alto Networks PAN-OS CVE-2012-6601 Remote Arbitrary Shell Command Injection Vulnerability
BID:62121
Info
Palo Alto Networks PAN-OS CVE-2012-6601 Remote Arbitrary Shell Command Injection Vulnerability
| Bugtraq ID: | 62121 |
| Class: | Unknown |
| CVE: |
CVE-2012-6601 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 27 2012 12:00AM |
| Updated: | Apr 27 2012 12:00AM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
Paloaltonetworks PAN-OS 4.1.3 Paloaltonetworks PAN-OS 4.1.1 Paloaltonetworks PAN-OS 4.1 Paloaltonetworks PAN-OS 4.0.9 Paloaltonetworks PAN-OS 4.0.8 Paloaltonetworks PAN-OS 4.0.7 Paloaltonetworks PAN-OS 4.0.6 Paloaltonetworks PAN-OS 4.0.4 Paloaltonetworks PAN-OS 4.0.3 Paloaltonetworks PAN-OS 3.1.11 Paloaltonetworks PAN-OS 3.1.10 Paloaltonetworks PAN-OS 3.1.9 |
| Not Vulnerable: |
Paloaltonetworks PAN-OS 4.1.4 Paloaltonetworks PAN-OS 4.0.10 Paloaltonetworks PAN-OS 3.1.12 |
Discussion
Palo Alto Networks PAN-OS CVE-2012-6601 Remote Arbitrary Shell Command Injection Vulnerability
Palo Alto Networks PAN-OS is prone to a remote command-injection vulnerability because it fails to adequately sanitize user-supplied input data.
Remote attackers can exploit this issue to execute arbitrary shell commands in the context of the application.
The following versions are affected:
Palo Alto Networks PAN-OS 3.1.11 and prior
Palo Alto Networks PAN-OS 4.0.9 and prior
Palo Alto Networks PAN-OS 4.1.3 and prior
Palo Alto Networks PAN-OS is prone to a remote command-injection vulnerability because it fails to adequately sanitize user-supplied input data.
Remote attackers can exploit this issue to execute arbitrary shell commands in the context of the application.
The following versions are affected:
Palo Alto Networks PAN-OS 3.1.11 and prior
Palo Alto Networks PAN-OS 4.0.9 and prior
Palo Alto Networks PAN-OS 4.1.3 and prior
Solution / Fix
Palo Alto Networks PAN-OS CVE-2012-6601 Remote Arbitrary Shell Command Injection Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.