QID 731378

Date Published: 2024-04-12

QID 731378: Palo Alto Networks (PAN-OS) Command Injection Vulnerability (PAN-252214) (Zero Day)

PAN-OS is the software that runs all Palo Alto Networks next-generation firewalls.

A command injection vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software for specific PAN-OS versions and distinct feature configurations may enable an unauthenticated attacker to execute arbitrary code with root privileges on the firewall.

Affected Versions:
PAN-OS 11.1 versions prior to PAN-OS 11.1.2-h3
PAN-OS 11.0 versions prior to PAN-OS 11.0.4-h1
PAN-OS 10.2 versions prior to PAN-OS 10.2.9-h1

NOTE: This issue applies only to PAN-OS 10.2, PAN-OS 11.0, and PAN-OS 11.1 firewalls with the configurations for both GlobalProtect gateway and device telemetry enabled.

QID Detection Logic (Authenticated):

This QID checks for the vulnerable version of PAN-OS by authenticating to the PanOS web UI and extracts the version from the response received.

Successful exploitation of the vulnerability may allow a remote unauthenticated attacker to execute arbitrary code with root privileges, leading to complete system compromise.

  • CVSS V3 rated as Critical - 10 severity.
  • CVSS V2 rated as Critical - 10 severity.
  • Solution
    There are no patches as of now, customers are advised to apply the mitigations mentioned in the vendor advisory. For more information, please refer to the Pan-OS Security Advisory

    Workaround:
    Recommended Mitigation:

    Customers with a Threat Prevention subscription can block attacks for this vulnerability by enabling Threat ID 95187 (introduced in Applications and Threats content version 8833-8682).

    In addition to enabling Threat ID 95187, customers must ensure vulnerability protection has been applied to their GlobalProtect interface to prevent exploitation of this issue on their device. Please see 340184 for more information.

    If you are unable to apply the Threat Prevention based mitigation at this time, you can still mitigate the impact of this vulnerability by temporarily disabling device telemetry until the device is upgraded to a fixed PAN-OS version. Once upgraded, device telemetry should be re-enabled on the device.

    Please see the following page for details on how to temporarily disable device telemetry:
    Disable Device Telemetry

    Vendor References

    CVEs related to QID 731378

    Software Advisories
    Advisory ID Software Component Link

    © CVE.report 2026

    Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

    CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

    Free CVE JSON API cve.report/api

    CVE.report and Source URL Uptime Status status.cve.report