CVE-2017-15940
The web interface packet capture management component in Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 allows remote authenticated users to execute arbitrary code via unspecified vectors.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (4.93%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The web interface packet capture management component in Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 allows remote authenticated users to execute arbitrary code via unspecified vectors.
- CVSS 3.0
- 9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 4.93% probability · 92th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-77
- Affected
- paloaltonetworks/pan-os
- Source
- cve@mitre.org
References
- http://www.securityfocus.com/bid/102076Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1040006Third Party Advisory, VDB Entry
- https://security.paloaltonetworks.com/CVE-2017-15940
- http://www.securityfocus.com/bid/102076Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1040006Third Party Advisory, VDB Entry
- https://security.paloaltonetworks.com/CVE-2017-15940
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.