Palo Alto Networks PAN-OS是美国Palo Alto Networks公司的一套为其防火墙设备开发的操作系统。 Palo Alto Networks PAN-OS存在安全漏洞,该漏洞源于软件SCEP (Simple Certificate Enrollment Protocol)特性中的OS命令注入漏洞,允许未经身份验证的基于网络的攻击者可利用该漏洞使用root用户特权执行任意代码,这些攻击者可利用该漏洞对防火墙配置有特定的了解。攻击者可利用该漏洞必须通过网络访问GlobalProt
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Palo Alto Networks | PAN-OS | 8.1 ~ 8.1.20-h1 | - |
|
| Palo Alto Networks | Prisma Access | 2.1 Preferred | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Clone from gist | https://github.com/timb-machine-mirrors/rqu1-cve-2021-3060.py | POC Details |
| 2 | CVE-2021-3060 | https://github.com/anmolksachan/CVE-2021-3060 | POC Details |
No public POC found.
Login to generate AI POC| CVE-2021-3064 | 9.8 CRITICAL | PAN-OS: Memory Corruption Vulnerability in GlobalProtect Portal and Gateway Interfaces |
| CVE-2021-3058 | 8.8 HIGH | PAN-OS: OS Command Injection Vulnerability in Web Interface XML API |
| CVE-2021-3056 | 8.8 HIGH | PAN-OS: Memory Corruption Vulnerability in GlobalProtect Clientless VPN During SAML Authen |
| CVE-2021-3062 | 8.1 HIGH | PAN-OS: Improper Access Control Vulnerability Exposing AWS Instance Metadata Endpoint to G |
| CVE-2021-3059 | 8.1 HIGH | PAN-OS: OS Command Injection Vulnerability When Performing Dynamic Updates |
| CVE-2021-3063 | 7.5 HIGH | PAN-OS: Denial-of-Service (DoS) Vulnerability in GlobalProtect Portal and Gateway Interfac |
| CVE-2021-3061 | 6.4 MEDIUM | PAN-OS: OS Command Injection Vulnerability in the Command Line Interface (CLI) |
No comments yet