Vulnerability Fixed in Palo Alto Networks PAN-OS (advisories.ncsc.nl)
0xBASE INTEL BRIEF
- Buffer overflow in PAN-OS User-ID Authentication Portal
- Unauthenticated remote code execution as root
- Affects PA-Series and VM-Series; Prisma Access, Cloud NGFW, Panorama not affected
- Limited exploitation targeting internet-exposed portals
"Palo Alto Networks has fixed a buffer overflow vulnerability in the User-ID Authentication Portal component of PAN-OS. Unauthenticated attackers can execute arbitrary code with root privileges. Affected are PA-Series and VM-Series firewalls; Prisma Access, Cloud NGFW, and Panorama are not vulnerable. Exposure of the portal to the internet is not recommended. Limited exploitation targeting exposed portals has been observed."
no comments yet.