An OS command injection vulnerability in the XML API of Palo Alto Networks PAN-OS software enables an authenticated API user to disrupt system processes and potentially execute arbitrary code with limited privileges on the firewall.
2023-12-13T19:15:09.640
2024-11-21T08:44:34.293
Modified
CVSSv3.1: 5.5 (MEDIUM)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Operating System | paloaltonetworks | pan-os | < 8.1.24 | Yes |
| Operating System | paloaltonetworks | pan-os | < 9.0.17 | Yes |
| Operating System | paloaltonetworks | pan-os | < 9.1.15 | Yes |
| Operating System | paloaltonetworks | pan-os | < 10.0.12 | Yes |
| Operating System | paloaltonetworks | pan-os | < 10.1.6 | Yes |