Palo Alto Networks PAN-OS是美国Palo Alto Networks公司的一套为其防火墙设备开发的操作系统。 Palo Alto Networks PAN-OS存在缓冲区错误漏洞,该漏洞源于User-ID Authentication Portal服务在处理特定数据包时的边界检查不足。未经身份认证的攻击者可通过向目标防火墙的User-ID Authentication Portal服务发送特制的数据包,触发缓冲区溢出,从而在目标设备上以 root 权限执行任意代码。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Palo Alto Networks | Cloud NGFW | All |
unaffected |
| Palo Alto Networks | PAN-OS | 12.1.0< 12.1.7 |
affected |
11.2.0< 11.2.12 |
affected | ||
11.1.0< 11.1.15 |
affected | ||
10.2.0< 10.2.18-h6 |
affected | ||
| Palo Alto Networks | Prisma Access | All |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Palo Alto Networks | Cloud NGFW | - | - |
|
| Palo Alto Networks | PAN-OS | 12.1.0 ~ 12.1.7 |
cpe:2.3:o:palo_alto_networks:pan-os:12.1.6:*:*:*:*:*:*:*
|
|
| Palo Alto Networks | Prisma Access | - | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No comments yet