QID 730274
Date Published: 2021-11-23
QID 730274: Palo Alto Networks (PAN-OS) OS Command Injection Vulnerability (PAN-176618)
PAN OS is the software that runs all Palo Alto Networks next-generation firewalls.
An OS command injection vulnerability in the Palo Alto Networks PAN-OS management interface exists when performing dynamic updates. This vulnerability enables a man-in-the-middle attacker to execute arbitrary OS commands to escalate privileges.
Affected Version:
PAN-OS 8.1 versions earlier than PAN-OS 8.1.20-h1;
PAN-OS 9.0 versions earlier than PAN-OS 9.0.14-h3;
PAN-OS 9.1 versions earlier than PAN-OS 9.1.11-h2;
PAN-OS 10.0 versions earlier than PAN-OS 10.0.8;
PAN-OS 10.1 versions earlier than PAN-OS 10.1.3.
QID Detection Logic (Authenticated):
This QID looks for the vulnerable version of PAN-OS
NOTE: This issue is applicable only to firewalls and Panoramas that receive dynamic updates from an update server
An OS command injection vulnerability in the Palo Alto Networks PAN-OS management interface exists when performing dynamic updates. This vulnerability enables a man-in-the-middle attacker to execute arbitrary OS commands to escalate privileges.
Refer to PAN-176618 for more information about patching this vulnerability.Workaround:
Updating dynamic content from a local file will prevent exposure to this vulnerability until you are able to upgrade PAN-OS firewalls and Panorama to a fixed version. You can disable scheduled dynamic updates in the web interface.
Push content updates from Panorama to the managed firewalls until you are able to upgrade PAN-OS to a fixed version. The process of upgrading dynamic content on managed devices is referenced here:
https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-web-interface-help/panorama-web-interface/panorama-managed-devices-summary/firewall-software-and-content-updates.html
- PAN-176618 -
security.paloaltonetworks.com/CVE-2021-3059
CVEs related to QID 730274
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| PAN-176618 |
|