Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2021-3060


An OS command injection vulnerability in the Simple Certificate Enrollment Protocol (SCEP) feature of PAN-OS software allows an unauthenticated network-based attacker with specific knowledge of the firewall configuration to execute arbitrary code with root user privileges. The attacker must have network access to the GlobalProtect interfaces to exploit this issue. This issue impacts: PAN-OS 8.1 versions earlier than PAN-OS 8.1.20-h1; PAN-OS 9.0 versions earlier than PAN-OS 9.0.14-h3; PAN-OS 9.1 versions earlier than PAN-OS 9.1.11-h2; PAN-OS 10.0 versions earlier than PAN-OS 10.0.8; PAN-OS 10.1 versions earlier than PAN-OS 10.1.3. Prisma Access customers with Prisma Access 2.1 Preferred and Prisma Access 2.1 Innovation firewalls are impacted by this issue.


Published

2021-11-10T17:15:10.157

Last Modified

2024-11-21T06:20:52.560

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 8.1 (HIGH)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:C/I:C/A:C

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

8.6

Impact Score

10.0

Weaknesses
  • Type: Secondary
    CWE-78
  • Type: Primary
    CWE-78

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application paloaltonetworks prisma_access 2.1 Yes
Application paloaltonetworks prisma_access 2.1 Yes
Operating System paloaltonetworks pan-os ≤ 8.1.20 Yes
Operating System paloaltonetworks pan-os ≤ 9.0.14 Yes
Operating System paloaltonetworks pan-os ≤ 9.1.11 Yes
Operating System paloaltonetworks pan-os < 10.0.8 Yes
Operating System paloaltonetworks pan-os < 10.1.3 Yes

References