Remote Code Execution in PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11-h1 and earlier, and PAN-OS 8.1.2 and earlier with GlobalProtect Portal or GlobalProtect Gateway Interface enabled may allow an unauthenticated remote attacker to execute arbitrary code.
The product uses a function that accepts a format string as an argument, but the format string originates from an external source.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Pan-os | Paloaltonetworks | * | 7.1.19 (excluding) |
Pan-os | Paloaltonetworks | 8.0.0 (including) | 8.0.12 (excluding) |
Pan-os | Paloaltonetworks | 8.1.0 (including) | 8.1.3 (excluding) |