Horizon Alert
Summary of the vulnerability and why it matters
The GlobalProtect feature within Palo Alto Networks PAN-OS is susceptible to a command injection flaw. This weakness allows an unauthorized external attacker to execute arbitrary code with the highest level of system privileges on the affected firewall. The impact can include unauthorized system control, data compromise, and disruption of network services.
- GlobalProtect feature in PAN-OS
- Arbitrary file creation leading to command injection
- Unauthorized system access and control
Attack Path
How an attacker could exploit the issue
This vulnerability allows an unauthenticated attacker to create arbitrary files on a targeted firewall. This file creation can then be leveraged to inject and execute commands with root privileges on the affected system. The outcome of this attack could be unauthorized code execution and system compromise.
- Exposure: A firewall with the GlobalProtect feature enabled.
- Attacker access: An unauthenticated remote attacker.
- Trigger and result: Arbitrary file creation leading to command execution.
Live Threat
Current exploitation, exposure, and threat context
This vulnerability presents a critical risk to organizations utilizing specific versions of Palo Alto Networks PAN-OS software with the GlobalProtect feature. The threat actor could exploit this to execute arbitrary code with root privileges on the firewall, leading to a significant compromise of systems and data. Organizations should prioritize addressing this vulnerability due to its severity and potential for widespread impact.
- Attacker skill: Low
- Access needed: Network access
- Business risk: Critical
Priority actions
Operational Fix
Recommended remediation, mitigation, and detection steps
A critical command injection vulnerability in Palo Alto Networks PAN-OS, specifically within the GlobalProtect feature, could allow an unauthenticated attacker to gain root privileges on firewalls. This could lead to the execution of arbitrary code, posing a significant risk to affected organizations. The vulnerability impacts certain PAN-OS versions and configurations, but not Cloud NGFW, Panorama appliances, or Prisma Access.
- Identify all PAN-OS assets with GlobalProtect enabled.
- Apply vendor-provided mitigations and fixes.
- Verify remediation and monitor for related activity.