CyberzSOC

Publication detail
← Back to advisories & guidance

2024-098: Command Injection Vulnerability in PaloAlto PAN-OS ↗ source

September 16, 2024 CERT-EU Advisory

Summary

If exploited, this flaw could allow an authenticated attacker to execute arbitrary commands as root on the firewall. The vulnerability CVE-2024-8686, with a CVSS score of 8.6, is a command injection vulnerability in Palo Alto Networks PAN-OS software. It enables an authenticated administrator to bypass system restrictions and run arbitrary commands as root on the firewall. CERT-EU strongly recommends updating affected PAN-OS installations to the latest version [1].

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2024-8686 8.6 High Palo Alto Networks PAN-OS A command injection vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to bypass system restrictions and run …

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.